Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
- ID
- 27204
- Status
- summarized
- Published
- 22 Sep 2026, 5:38 PM
- Fetched
- 22 Sep 2026, 8:16 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/malicious-npm-package-indexed-btree-hid.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 22 Sep 2026, 8:21 PM
- Tags
- Audience
- developersvibe_codersdatabase_learners
What happened
A malicious npm package called 'indexed-btree' mimicked the legitimate 'sorted-btree' package and hid its malware loader inside a runtime method (BTree.prototype.set()) instead of using preinstall/postinstall lifecycle scripts, bypassing npm v12's new security controls. The package amassed millions of downloads since June 18, 2026, and reportedly earned the attacker ~€230,933 (109 ETH) before removal. It used EtherHiding to pull encrypted payloads from a Sepolia testnet smart contract and beaconed host fingerprints to Slack and Telegram.
Why it matters
If you rely on npm v12's lifecycle script blocking as a supply-chain defense, this package proves attackers have already moved to runtime-embedded malware inside library functions. Audit dependency trees for typosquatted packages like 'indexed-btree' vs 'sorted-btree', and consider runtime sandboxing or lockfile review rather than trusting install-time controls alone.
Discussion angle
npm v12 blocked lifecycle scripts—so attackers embedded malware in a B-tree set() method instead. What runtime-level defenses (sandboxing, CSP, dependency allowlists) actually catch this class of attack?