Malicious npm Package With 2 Million Downloads Hides Malware in Runtime Code
Malicious npm package 'indexed-btree' with 2M weekly downloads hides runtime malware using blockchain-based command-and-control.
A malicious npm package named 'indexed-btree', impersonating the legitimate 'sorted-btree' library, was discovered with nearly two million weekly downloads. The malware bypasses standard install-time detection by activating during runtime method execution rather than preinstall/postinstall scripts. Researchers at Checkmarx found the campaign uses an Ethereum Sepolia smart contract for command-and-control infrastructure, making takedowns more difficult.