Security2 publishers2 min readPublished
Malicious indexed-btree package moves npm malware from install scripts to first use
Attackers hid the malware trigger in the indexed-btree npm package inside a library method, sidestepping the install-script block npm 12 shipped in July. Install-time checks, including a look at package.json for hooks, pass a package that runs its payload on first use.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The loader sits in btree.prototype.set and runs with the same permissions and network access as the host application, according to Suzu Labs' Jacob Krell.
- Once running, it fingerprints the host, sends stolen data out over Slack and Telegram, and takes commands through an Ethereum smart contract.
- indexed-btree imitates the legitimate sorted-btree library and anchors what researchers describe as an ongoing npm supply chain campaign.
- Its authors built a plausible GitHub repository with commit history and a developer profile with a photo, and that repository contains none of the malicious code.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A pipeline that installs with scripts disabled can still carry the package into a production service, where the payload can reach credentials, internal systems and customer data.
- constraint Clearing a new dependency now means reading or executing its library code, a slower step than checking package.json for install hooks.
- decision SCA blocklists cover indexed-btree only after it is flagged, so teams have to decide whether to pay for dynamic testing of running applications to catch the next lookalike.
Darren Meyer, a research advocate at Checkmarx, said npm's change was meant to cut off exactly this class of malware [4]. "Attackers just moved to a new vector," he said [6]. Bruno Dias described the package and its trigger on Checkmarx's application security testing blog [3]. The victim's side of infection takes one step. A project adds indexed-btree and calls it [3].
Waseem Ahmed, head of engineering at Secure.com, said some researchers warned when npm shipped the change that the code still has to run at some point [7]. "If you close the door at install time, a patient attacker moves one step downstream and runs it at import time instead," he said [8]. He also said the absence of an install script had become a trust signal for reviewers [9]. "So the single heuristic that npm's change encouraged people to rely on is exactly the heuristic this defeats," Ahmed said [10].
Jacob Krell of Suzu Labs said a clean install tells a user only that the package manager saw nothing suspicious [14]. Sonu Kapoor, a senior Angular consultant at Solid Software Solutions, said a dependency can wait until the application uses it [11]. "That delay matters because the malicious activity can blend into normal application execution," Kapoor said [12]. "That makes relying solely on installation-time security checks insufficient," said Jason Soroko, a senior fellow at Sectigo [15].
Aviram Jenik, CEO of KhaiCode, called the package a "sleeper cell" [16]. "This makes it borderline impossible to detect by any static analysis tools, which will not see this path activated. The only way to detect this is by actively running the application with dynamic analysis," he said [17]. The code an analyst has to find ships in the package npm serves, inside the library's own prototype method [3].
Scope is thin. The ReversingLabs account names one package and calls the activity an ongoing campaign [2]. It does not give a download count, a victim count, a start date, an attributed actor or a second package [21]. On the published record, the campaign consists of one package [22].
The npm 12 default still does its job. Boris Cipot, a security engineer at Black Duck Software, said blocking preinstall and postinstall scripts removes an important attack route but does not make the package itself trustworthy [19].
What to watch
- A published list of further npm packages that hide their trigger in library methods, tying indexed-btree to a sustained operation by one actor.
- Release of the Ethereum contract address or Slack and Telegram indicators that would let defenders hunt for related packages.
- Download or victim counts for indexed-btree from Checkmarx or npm.