Malicious npm packages evade install-script defenses at runtime
Npm malware campaign uses 'indexed-btree' package to bypass security measures, collecting system details and exfiltrating data.
Intelligence analysis by Qwen 2.5 (3B)

Researchers found a malicious npm package that evaded security defenses by hiding in a package's runtime behavior, collecting system details and exfiltrating data through hardcoded channels.
A bad guy made a package called 'indexed-btree' that looks like a normal package. But it secretly does bad things when you use it. It steals information from your computer and sends it to bad guys. The good guys found out and told everyone to be careful.
Analysis
{"heading_1":"The Malicious 'indexed-btree' Package","paragraph_1":"The 'indexed-btree' package, spotted by Checkmarx researchers, impersonates the legitimate 'sorted-btree' library and has amassed 2 million weekly downloads. It bypasses npm security measures by hiding its loader in the package's BTree.prototype.set() method, which executes at runtime.","paragraph_2":"The package's runtime trigger is a well-built way to sneak past standard taint-analysis tools and most static scanners, as it hides inside the library's own BTree.prototype.set method, which is the main function that every user would call constantly.","paragraph_3":"The malware collects system details, including architecture, hostname, CPU, memory, and uptime, and exfiltrates the information through hardcoded Slack and Telegram channels. It also polls an Ethereum smart contract for C2 information and uses X25519 key exchange to derive an AES key and decrypt a second-stage payload stored in the contract.","paragraph_4":"The threat actors have gone to great lengths to make the project appear legitimate, including building a legitimate-looking GitHub repository, populating its commit history, and curating the developer account.","paragraph_5":"The researchers note that the threat actors have gone to great lengths to make the project appear legitimate, including building a legitimate-looking GitHub repository, populating its commit history, and curating the developer account."}
Key points
- The 'indexed-btree' package impersonates the legitimate 'sorted-btree' library and has amassed 2 million weekly downloads.
- The package hides its loader in the package's BTree.prototype.set() method, which executes at runtime.
- The malware collects system details, including architecture, hostname, CPU, memory, and uptime, and exfiltrates the information through hardcoded channels.
By using runtime behavioral analysis, developers can better detect and prevent such attacks, ensuring the security of their applications.
The bad guys might continue to find new ways to hide their malicious packages, making it harder for developers to protect their applications.



