indexed-btree npm campaign hid runtime loader in BTree code, evading install-script defenses across ten packages
Checkmarx says typosquatted npm package indexed-btree (near 2M weekly downloads) hid its loader in BTree.prototype.set() to bypass npm v12 install-script rules, exfiltrating via Slack/Telegram and using a Sepolia Ethereum smart contract for C2; ten packages…
Checkmarx reported that indexed-btree, uploaded to npm on June 18, 2026 by user charlessadler25 and impersonating the legitimate sorted-btree library, reached nearly 2 million weekly downloads while hiding an obfuscated loader inside BTree.prototype.set() that fires only when an application calls the method with a specific key — sidestepping the lifecycle-script approval requirements npm v12 has enforced since June 2026 and evading most static and taint-analysis scanners. Legitimacy was faked through a curated GitHub repository with an extensive commit history and, per CSO Online, an AI-generated profile image. Once triggered, the loader fingerprints the host (architecture, hostname, CPU, memory, uptime), exfiltrates details to a hardcoded Slack channel and Telegram bot, and polls an Ethereum Sepolia testnet smart contract whose getter/setter functions serve as takedown-resilient command-and-control (The Hacker News calls the technique EtherHiding), using X25519 key exchange and AES to decrypt a second stage assembled from encrypted contract chunks before deleting artifacts. Ten packages were removed from npm — the primary plus nine related ones including btree-core (1.95 million downloads per BleepingComputer; 1.9M+ per CSO Online), btree-lru-cache, and sliding-score-window — with SecurityWeek reporting the nine related packages accumulated over 5 million downloads and calling the campaign ongoing as of 2026-09-22, while other outlets say only millions collectively. Ill-gotten gains are reported inconsistently: BleepingComputer says the operators' wallet holds 109 ETH, The Hacker News says about €230,933 (109 ETH), and SecurityWeek says an apparent profit of roughly $300,000 (109 ETH), adding that the same smart contract was previously seen in the mutex-forge campaign. GBHackers rated indexed-btree as critical with 9.3 severity. IOCs were shared, and developers are urged to rotate secrets and rebuild compromised environments. Separately within the same reporting window: ReversingLabs disclosed tw-pkgprobe-7731, a mid-August 2026 npm package by account twdepprobe7731 that published 11 versions in about 45 minutes, claimed to be an authorized Twilio HackerOne bug-bounty probe, and whose versions 1.0.1–1.0.4 exfiltrated Twilio ACCOUNT_SID and AUTH_TOKEN (later builds probed Twilio hosts and the AWS instance metadata service); The Hacker News also relayed a Socket report on North Korea-linked PolinRider compromising the Packagist package…
- indexed-btree impersonated the legitimate sorted-btree library; The Hacker News reports it was uploaded June 18, 2026 by npm user charlessadler25
- Loader hidden in BTree.prototype.set() executes only at runtime when called with a specific key, bypassing npm v12's June 2026 install-script approval requirements and most static and taint-analysis scanners
- First stage fingerprints the host (architecture, hostname, CPU, memory, uptime) and exfiltrates it to a hardcoded Slack channel and Telegram bot/chat
- C2 address hidden in an Ethereum Sepolia testnet smart contract with getter/setter polling; second stage decrypted via X25519 key exchange and AES (technique dubbed EtherHiding by The Hacker News); artifacts deleted afterward
- indexed-btree reached nearly 2 million weekly downloads before discovery; GBHackers classified it as critical with 9.3 severity
- Ten packages removed from npm: indexed-btree plus nine related ones including btree-core (1.95M downloads per BleepingComputer; 1.9M+ per CSO Online), btree-lru-cache, and sliding-score-window
- Download totals for the nine related packages are disputed: SecurityWeek says 5+ million; other outlets say only millions collectively
- Operators' wallet holds 109 ETH; valuation reported inconsistently as €230,933 (The Hacker News) or about $300,000 (SecurityWeek)
Coverage timelineoldest first · each row is one article
- · 6d agoMalicious npm packages evade install-script defenses at runtime
BleepingComputer· 78
Malicious npm package 'indexed-btree' hides a loader in runtime code to evade install-script defenses, reaching 2 million weekly downloads alongside nine related packages.
- · 5d ago10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads
GBHackers· 68
10 malicious npm packages with millions of downloads bypass install-time checks by loading malware at runtime, using Ethereum for C2.
- · 5d agoMalicious npm Package With 2 Million Downloads Hides Malware in Runtime Code
Cyber Security News· 75