{"id":3051,"date":"2026-09-22T10:54:40","date_gmt":"2026-09-22T10:54:40","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3051"},"modified":"2026-09-22T10:54:40","modified_gmt":"2026-09-22T10:54:40","slug":"malicious-npm-package-indexed-btree-hid-its-loader-in-runtime-code-before-removal","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3051","title":{"rendered":"Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjaN7aXt0PoPdZQ_VG77wkwdIyNugcdkFD6MnMvlj5LN_byw2ZrX8-gtpDld4CviuW1MOhHiElsvFtIkO9IfhBr4af-sJwM1zvR-RFICRll4G5jG4JNPX1vx4sup3omlw8uTJgro9UUfzecLMI1Whls3ihqZ9OXYJliIBjhpoodf4WI9j1lA6EUjms7x1pG\/s1700-nu-rw-lo-l85-e365\/rth.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A malicious npm package named \u00abindexed-btree\u00bb has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.<\/p>\n<p>\u00abIndexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree\/indexing utility,\u00bb Checkmarx <a href=\"https:\/\/checkmarx.com\/zero-post\/npm-btree-malware-campaign-affects-millions-of-downloads-no-need-for-install-script\/\" target=\"_blank\">said<\/a>. \u00abUnlike the common attacks we&#8217;ve seen in the supply chain space, this package does not rely on preinstall \/ postinstall at all. Instead, it runs entirely from application code at runtime.\u00bb<\/p>\n<p>The <a href=\"https:\/\/www.npmjs.com\/package\/indexed-btree\" target=\"_blank\">package<\/a> and the <a href=\"https:\/\/github.com\/INDEXED-BTREE\/\" target=\"_blank\">associated GitHub repository<\/a> are no longer available for download from npm. However, statistics show the package was first uploaded to the registry on June 18, 2026, by an npm user named \u00ab<a href=\"https:\/\/www.npmjs.com\/~charlessadler25\" target=\"_blank\">charlessadler25<\/a>,\u00bb amassing <a href=\"https:\/\/npm-stat.com\/charts.html?package=indexed-btree&amp;from=2026-06-01&amp;to=2026-09-21\" target=\"_blank\">millions of downloads<\/a> in a <a href=\"https:\/\/secure.software\/npm\/packages\/indexed-btree\/versions\" target=\"_blank\">short span of time<\/a>.<\/p>\n<p>To make matters worse, the campaign may have generated illicit profits for the threat actor, earning them around \u20ac230,933.57 in cryptocurrency (i.e., 109 ETH).<\/p>\n<p>The development comes as npm version 12 introduced a security change to prevent automatic execution of lifecycle scripts such as preinstall or postinstall, which is one of the most common ways malware is executed through packages distributed through the repository.<\/p>\n<p>\u00abLegitimately, these are often used for compiling necessary code, seeding data, or setting up essential configurations,\u00bb Checkmarx <a href=\"https:\/\/checkmarx.com\/zero-post\/npm-v12-lifecycle-script-limits-a-real-malicious-package-risk-reduction-or-just-moving-risk-around\/\" target=\"_blank\">said<\/a>. \u00abFor threat actors, however, this is frequently exploited to automatically execute malicious code without user consent during the installation of a malicious package.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The latest findings from the software supply chain security company show that bad actors are shifting tactics in response to the change, eschewing install hooks in favor of incorporating the malicious code directly within the library.<\/p>\n<p>In this case, the malware loader is concealed inside a \u00abBTree.prototype.set()\u00bb method, which then triggers \u00absharedLoad.min.js,\u00bb a JavaScript payload that embeds the obfuscated first stage of the malware.<\/p>\n<p>The malware is designed to fingerprint the host, beacon the details to a hard-coded Slack channel and Telegram bot, uses the <a href=\"https:\/\/thehackernews.com\/2026\/09\/clickfix-lures-deploy-chainscript-rat.html\" target=\"_blank\">EtherHiding technique to pull next-stage, encrypted blobs from a <a href=\"https:\/\/sepolia.etherscan.io\/address\/0xE390863Dac96a7118C71227C2b099B50cF602D31\" target=\"_blank\">smart contract<\/a> deployed on Sepolia testnet, and finally merge them to form the second-stage payload.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhoQ4QnAmd_sMorsoejvt0jz-FEMOPMkFCRT06sluWF15hdEr_mBBM8jEp8k9HRT1ZoPLjjTMlnHYGU3_6lMIgCBVDf0LTS7u2uqOQAFGtvAhU1kd1mLi8I3EJk1MJK5G4gu3ef1Eb2lX_ipkFa9Bl_pF1MtxyjOMeghoQriHY5HWt04w7srqk67y7KpbmN\/s1700-nu-rw-lo-l85-e365\/git-make.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhoQ4QnAmd_sMorsoejvt0jz-FEMOPMkFCRT06sluWF15hdEr_mBBM8jEp8k9HRT1ZoPLjjTMlnHYGU3_6lMIgCBVDf0LTS7u2uqOQAFGtvAhU1kd1mLi8I3EJk1MJK5G4gu3ef1Eb2lX_ipkFa9Bl_pF1MtxyjOMeghoQriHY5HWt04w7srqk67y7KpbmN\/s1700-nu-rw-lo-l85-e365\/git-make.jpg\" alt=\"\" border=\"0\" data-original-height=\"955\" data-original-width=\"1594\"\/><\/a><\/div>\n<p>The final step involves deleting the malicious artifacts and removing the trigger from the package code to cover up the tracks.<\/p>\n<p>Checkmarx said indexed-btree is one of the many npm packages tied to the same operation, all of which have since been removed from npm &#8211;<\/p>\n<ul>\n<li>ordered-kv-index<\/li>\n<li>btree-leaderboard<\/li>\n<li>priority-slot-queue<\/li>\n<li>btree-range-store<\/li>\n<li>btree-core<\/li>\n<li>btree-time-index<\/li>\n<li>btree-lru-cache<\/li>\n<li>neighbor-key-map<\/li>\n<li>sliding-score-window<\/li>\n<li>mutex-forge<\/li>\n<\/ul>\n<p>To counter the threat, developers are recommended not to stick only to install-time scanning and blocking lifecycle scripts alone, but also employ runtime behavior analysis.<\/p>\n<p>\u00abWhat makes this campaign particularly important is that it shows attackers adapting almost immediately to stronger software supply chain defenses,\u00bb Ensar Seker, CISO at SOCRadar, said in a statement shared with The Hacker News. \u00abNpm has improved install time security by restricting dependency lifecycle scripts, but this campaign demonstrates that attackers can simply move malicious execution into legitimate-looking runtime functionality instead.\u00bb<\/p>\n<p>\u00abThe broader lesson is that security controls change attacker behavior rather than eliminate the underlying threat. Blocking lifecycle scripts is an important improvement, but attackers will continue searching for alternative execution paths. Defenders, therefore, need layered controls capable of detecting malicious behavior before installation, during execution, and after deployment.\u00bb<\/p>\n<h3>PolinRider Resurfaces on Packagist<\/h3>\n<p>The disclosure comes as Socket said it deleted malicious code in the \u00abdev-main\u00bb version of \u00abvisanduma\/nova-two-factor,\u00bb a Packagist package with over 700,000 cumulative downloads, as part of an ongoing North Korea-linked malicious cyber campaign dubbed PolinRider.<\/p>\n<p>A defining trait of PolinRider is the threat actor&#8217;s pattern of compromising developer accounts to inject malicious content into source code repositories and employ routine developer actions, such as cloning a repository or opening it in an integrated development environment (IDE), as triggers to activate the infection chain.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>This often entails rewriting Git history, concealing payloads within configuration or font files, setting up malicious VS Code auto-run tasks, and relying on takedown-resistant techniques like EtherHiding and its stealth-focused successor, NullReceiver, for <a href=\"https:\/\/www.sonatype.com\/blog\/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads\" target=\"_blank\">staged-payload delivery<\/a> via the blockchain.<\/p>\n<p>\u00abAnalysis of the Visanduma GitHub organization indicates that its repositories have been compromised since mid-June 2026,\u00bb Socket security researcher Karlo Zanki <a href=\"https:\/\/socket.dev\/blog\/polinrider-github-packagist\" target=\"_blank\">said<\/a>. \u00abThe malicious changes were introduced through the <a href=\"https:\/\/github.com\/lahirulhr\" target=\"_blank\">LaHiRu<\/a> developer account.\u00bb<\/p>\n<p>One notable shift observed in the latest iteration is the direct insertion of heavily obfuscated JavaScript into \u00abindex.php\u00bb and its execution through PHP&#8217;s \u00ab<a href=\"https:\/\/www.php.net\/manual\/en\/function.shell-exec.php\" target=\"_blank\">shell_exec()<\/a>\u00bb function. This approach, besides allowing a PHP entry point to invoke the JavaScript infection chain, suggests the threat actors are adapting their execution methods based on the compromised project instead of using a fixed delivery path.<\/p>\n<p>\u00abThe activity reinforces a defining characteristic of PolinRider: package-registry compromise is often a consequence of a broader Git-based intrusion rather than the campaign&#8217;s primary objective,\u00bb Socket said. \u00abThe operators use ordinary source-code collaboration to reach developer environments, spread into additional repositories, and maintain access over time.\u00bb<\/p>\n<p>\u00abCompromised source repositories give the operators opportunities to infect contributors, access private projects, and propagate through normal development workflows. Package publication becomes an additional distribution path when a compromised repository produces a new release.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A malicious npm package named \u00abindexed-btree\u00bb has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3052,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[10,2230,3496,449,33,39,40,1825,3284],"class_list":["post-3051","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-code","tag-hid","tag-indexedbtree","tag-loader","tag-malicious","tag-npm","tag-package","tag-removal","tag-runtime"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3051","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3051"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3051\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3052"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3051"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3051"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3051"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}