Malicious B-tree NPM Package Accumulates Millions of Downloads
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Industries
- SaaS & technology
- Reported by
- 1 outlet
The NPM ecosystem has suffered another supply chain attack in which a malicious package has accumulated millions of downloads, Checkmarx reports.
Still ongoing, the campaign has managed to bypass NPM’s recent protections by hiding a malicious trigger in the package’s JavaScript prototype code, rather than using an install script that could be detected by security solutions.
Instead of targeting highly popular packages for fast propagation, and likely immediate detection, the threat actor built trust by creating a legitimate-looking GitHub repository.
The malicious package, indexed-btree, mimics the legitimate B-tree/indexing utility sorted-btree, and has reached 2 million weekly downloads before being detected, Checkmarx says.
To ensure the package’s popularity, the threat actor created a GitHub account and added seemingly legitimate commits to the indexed-btree repository.
“A GitHub repository is something that attackers don’t usually bother creating. This one is clever enough to not include the malicious code. Additionally, the presence of many commits can aid in making it look like a legit repository,” Checkmarx notes.
Advertisement. Scroll to continue reading.
The threat actor hid malicious code in the library’s main function, the BTree.prototype.set method, to trigger JavaScript code containing the malware’s first stage.
Once executed, the malware collects system information and sends it to a hardcoded Slack channel and Telegram chat, connects to a blockchain contract deployed on Sepolia that serves as its command-and-control (C&C), extracts and decrypts the second stage from the contract, and cleans its traces.
According to Checkmarx, the attacker’s smart contract was previously found in the mutex-forge package, and the threat actor appears to have made 109 ETH (nearly $300,000).
In addition to indexed-btree, other packages linked to the supply chain campaign include ordered-kv-index, btree-leaderboard, priority-slot-queue, btree-range-store, btree-core, btree-time-index, btree-lru-cache, neighbor-key-map, and sliding-score-window, which had over 5 million downloads when removed.
“This ongoing campaign is a dynamic threat to organizations, with a resilient C&C and malicious code hidden inside package code,” Checkmarx notes.
Related: Rust Team Members and Popular Crate Owners Targeted via Video Calls
Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Related: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Related: Rust Supply Chain Attack Linked to North Korean Hackers
Originally published by SecurityWeek. © SecurityWeek. Written by Ionut Arghire.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-22 11:33 UTC
Related stories
- Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
Dark Reading · 2026-09-28
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
The Hacker News · 2026-09-28
- RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
The Hacker News · 2026-09-28
- Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
Dark Reading · 2026-09-28
- 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
BleepingComputer · 2026-09-28