Malicious B-tree NPM Package Accumulates Millions of Downloads
Ongoing NPM supply chain campaign hides malware in indexed-btree's prototype code, reaching 2 million weekly downloads before detection.
Checkmarx reports an ongoing NPM supply chain attack where indexed-btree, mimicking the legitimate sorted-btree library, reached 2 million weekly downloads by hiding its trigger in the BTree.prototype.set method instead of an install script, bypassing NPM protections. The first stage collects system information, exfiltrates it to a hardcoded Slack channel and Telegram chat, then retrieves and decrypts a second stage from a Sepolia blockchain smart contract serving as C2. Nine related packages (btree-core, btree-lru-cache, sliding-score-window, and others) accumulated over 5 million downloads before removal. A legitimate-looking GitHub repository with many commits built trust, and the actor's contract was previously seen in mutex-forge, with an apparent profit of 109 ETH (about $300,000).