discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Malicious npm packages evade install-script defenses at runtime

Npm malware campaign uses 'indexed-btree' package to bypass security measures, collecting system details and exfiltrating data.

By Bill Toulas·Sep 20·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Malicious npm packages evade install-script defenses at runtime
Image: bleepingcomputer.com

Researchers found a malicious npm package that evaded security defenses by hiding in a package's runtime behavior, collecting system details and exfiltrating data through hardcoded channels.

Why it matters

This finding highlights the need for developers to use runtime behavioral analysis in addition to install-time scanning to detect and prevent npm supply chain attacks.

A bad guy made a package called 'indexed-btree' that looks like a normal package. But it secretly does bad things when you use it. It steals information from your computer and sends it to bad guys. The good guys found out and told everyone to be careful.

Analysis

{"heading_1":"The Malicious 'indexed-btree' Package","paragraph_1":"The 'indexed-btree' package, spotted by Checkmarx researchers, impersonates the legitimate 'sorted-btree' library and has amassed 2 million weekly downloads. It bypasses npm security measures by hiding its loader in the package's BTree.prototype.set() method, which executes at runtime.","paragraph_2":"The package's runtime trigger is a well-built way to sneak past standard taint-analysis tools and most static scanners, as it hides inside the library's own BTree.prototype.set method, which is the main function that every user would call constantly.","paragraph_3":"The malware collects system details, including architecture, hostname, CPU, memory, and uptime, and exfiltrates the information through hardcoded Slack and Telegram channels. It also polls an Ethereum smart contract for C2 information and uses X25519 key exchange to derive an AES key and decrypt a second-stage payload stored in the contract.","paragraph_4":"The threat actors have gone to great lengths to make the project appear legitimate, including building a legitimate-looking GitHub repository, populating its commit history, and curating the developer account.","paragraph_5":"The researchers note that the threat actors have gone to great lengths to make the project appear legitimate, including building a legitimate-looking GitHub repository, populating its commit history, and curating the developer account."}

Key points

  • The 'indexed-btree' package impersonates the legitimate 'sorted-btree' library and has amassed 2 million weekly downloads.
  • The package hides its loader in the package's BTree.prototype.set() method, which executes at runtime.
  • The malware collects system details, including architecture, hostname, CPU, memory, and uptime, and exfiltrates the information through hardcoded channels.
The Upside

By using runtime behavioral analysis, developers can better detect and prevent such attacks, ensuring the security of their applications.

The Downside

The bad guys might continue to find new ways to hide their malicious packages, making it harder for developers to protect their applications.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritynpmsupply-chainmalwareruntime

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 20, 2026

Source

bleepingcomputer.com

Share

Topics

securitynpmsupply-chainmalwareruntime

Related

More from this desk

Oct 7·thehackernews.com

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

SonicWall has released hotfixes for four flaws in its SMA1000 appliances, including a serious SSRF bug rated 10.0 on the CVSS scale.

Oct 7·bleepingcomputer.com

Microsoft Outlook to block MSIX attachments starting November

Microsoft Outlook to block MSIX attachments starting November 2026.

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.