
indexed-btree npm Package Executes Malware Loader Inside BTree.prototype.set() After npm 12 Lifecycle Restrictions
indexed-btree executed its payload via legitimate-looking runtime methods after npm blocked install hooks, earning 109 ETH across multiple packages. The operation shows immediate attacker adaptation and underscores the need for runtime detection beyond static or install-time controls.
Checkmarx identified indexed-btree as a counterfeit of sorted-btree that performed all malicious activity at runtime. The set() method triggered sharedLoad.min.js, which loaded an obfuscated first stage that fingerprinted the host and retrieved encrypted blobs from a Sepolia smart contract. The campaign also published at least nine related packages, all since deleted, and accumulated millions of downloads in weeks.
npm 12's restriction on preinstall and postinstall scripts forced the shift. Technical telemetry shows the malware deleted its own artifacts and removed the trigger code after execution, a deliberate anti-forensics step not present in earlier lifecycle-script campaigns. This matches patterns seen in prior supply-chain operations where defenders blocked one vector and actors immediately relocated execution into application code.
The episode parallels the Comment2Shell WordPress exploitation, where a known input-handling flaw continued to yield remote code execution after patches because organizations relied on static detection rather than runtime behavioral controls. Both cases demonstrate that mitigation of one attack surface simply moves malicious behavior elsewhere unless layered monitoring is applied.
Developers must now instrument runtime behavior analysis across dependency graphs. Procurement records and contract awards for similar runtime monitoring tools indicate this requirement will spread to CI pipelines within the next two quarters.
SOCRadar: At least three additional runtime-execution npm packages from the same cluster will surface within 45 days.
Sources (3)
- [1]Checkmarx Research on indexed-btree(https://checkmarx.com/blog/npm-supply-chain-campaign-indexed-btree/)
- [2]Socket.dev Report on Packagist PolinRider(https://socket.dev/blog/packagist-polinrider-resurfaces)
- [3]npm Security Advisory on Lifecycle Scripts v12(https://github.com/npm/rfcs/blob/main/accepted/0049-lifecycle-scripts.md)