AI Weekly Malaysia

Back to items Summaries

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

ID
27204
Status
summarized
Published
22 Sep 2026, 5:38 PM
Fetched
22 Sep 2026, 8:16 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/malicious-npm-package-indexed-btree-hid.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
22 Sep 2026, 8:21 PM
Tags
Audience
developersvibe_codersdatabase_learners

What happened

A malicious npm package called 'indexed-btree' mimicked the legitimate 'sorted-btree' package and hid its malware loader inside a runtime method (BTree.prototype.set()) instead of using preinstall/postinstall lifecycle scripts, bypassing npm v12's new security controls. The package amassed millions of downloads since June 18, 2026, and reportedly earned the attacker ~€230,933 (109 ETH) before removal. It used EtherHiding to pull encrypted payloads from a Sepolia testnet smart contract and beaconed host fingerprints to Slack and Telegram.

Why it matters

If you rely on npm v12's lifecycle script blocking as a supply-chain defense, this package proves attackers have already moved to runtime-embedded malware inside library functions. Audit dependency trees for typosquatted packages like 'indexed-btree' vs 'sorted-btree', and consider runtime sandboxing or lockfile review rather than trusting install-time controls alone.

Discussion angle

npm v12 blocked lifecycle scripts—so attackers embedded malware in a B-tree set() method instead. What runtime-level defenses (sandboxing, CSP, dependency allowlists) actually catch this class of attack?

Top