Malicious npm packages bypass install-script
A malicious npm campaign impersonating a legitimate library evades GitHub's latest security measures by hiding malware in runtime code, not install

A malicious npm package named 'indexed-btree' has been caught impersonating the legitimate 'sorted-btree' library. According to researchers at Checkmarx, the package has amassed 2 million weekly downloads and demonstrates a new method for bypassing supply chain security defenses.
In June 2026, GitHub announced new npm security measures to block supply chain attacks. These measures prevent the automatic execution of dependency lifecycle scripts like 'preinstall' and 'postinstall' without explicit approval. They also stop npm from automatically fetching dependencies from Git repositories or remote URLs.
The malicious indexed-btree package sidesteps these protections entirely. It avoids installation scripts. Instead, it hides its malware loader inside the package's normal BTree.prototype.set() method. This method executes at runtime when an application calls it with a specific key value.
As a result, the installation process appears clean and does not trigger npm v12's approval mechanisms. "The malware loader hides inside the library's own BTree.prototype.set method, which is the main function that every user would call constantly," explains Checkmarx. This triggers an obfuscated first-stage payload.
Evasion and data collection
This technique is a well-built way to sneak past standard taint-analysis tools and most static scanners. Once executed, the malware collects detailed system information. This includes architecture, hostname, CPU, memory, and uptime. It exfiltrates this data through hardcoded Slack and Telegram channels.
The malware also establishes command-and-control. It polls an Ethereum smart contract on the Sepolia test network for instructions. It uses an X25519 key exchange to derive an AES key. This key decrypts a second-stage payload stored within the smart contract.
When the attack operators decide to end their campaign, the malware can delete its files. It also removes the malicious trigger from the package code to wipe its traces.
A coordinated campaign
Checkmarx researchers note the threat actors went to great lengths to appear legitimate. They built a convincing GitHub repository, populated its commit history, and curated the developer account. The campaign may have generated significant profits. The attackers use a wallet holding 109 ETH, though the report does not confirm these funds came from cryptocurrency theft.
Checkmarx discovered nine additional malicious npm packages linked to the same operation. Npm has now removed these packages. Their download numbers were significant.
| Package Name | Weekly Downloads |
|---|---|
| ordered-kv-index | 448,184 |
| btree-leaderboard | 493,685 |
| priority-slot-queue | 402,860 |
| btree-range-store | 468,092 |
| btree-core | 1,951,274 |
| btree-time-index | 425,312 |
| btree-lru-cache | 372,185 |
| neighbor-key-map | 366,019 |
| sliding-score-window | 448,024 |
Recommended defenses
Developers are advised not to rely solely on install-time scanning. They should also employ runtime behavioral analysis to catch such threats. Anyone who installed the indexed-btree package or any of the listed packages should take immediate action. They must rotate all secrets and restore their development environment from a known safe backup.
The campaign shows a shift in attacker tactics. By embedding malicious code in runtime functions, they bypass the latest vendor security advisories and automated defenses designed for the install phase.





