<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/malicious-npm-package-indexed-btree-bypassed-install-script-defenses-with-runtime-payload-aocxiiqm7" -->

---
title: Malicious npm package &#x27;indexed-btree&#x27; bypassed...
description: A malicious npm package named indexed-btree impersonated the legitimate sorted-btree library and accumulated nearly 2 million weekly downloads before Checkmarx...
canonical: https://daily.dev/posts/malicious-npm-package-indexed-btree-bypassed-install-script-defenses-with-runtime-payload-aocxiiqm7
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Malicious npm package &#x27;indexed-btree&#x27; bypassed install-script defenses with runtime payload | daily.dev
og:description: A malicious npm package named indexed-btree impersonated the legitimate sorted-btree library and accumulated nearly 2 million weekly downloads before Checkmarx...
og:url: https://daily.dev/posts/malicious-npm-package-indexed-btree-bypassed-install-script-defenses-with-runtime-payload-aocxiiqm7
og:image: https://api.daily.dev/og/posts/AocXIIQm7.png
og:image:alt: Malicious npm package &#x27;indexed-btree&#x27; bypassed install-script defenses with runtime payload
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Malicious npm package 'indexed-btree' bypassed install-script defenses with runtime payload

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 1 comments

## Summary

A malicious npm package named indexed-btree impersonated the legitimate sorted-btree library and accumulated nearly 2 million weekly downloads before Checkmarx identified it and npm removed it on September 3, 2026, about 11 weeks after the first malicious version appeared. The package bypassed GitHub's June 2026 preinstall/postinstall script blocking by hiding a malicious loader inside BTree.prototype.set(), a core method that legitimate users call during normal operation, meaning static scanners and taint-analysis tools saw nothing suspicious at install time. Once triggered by a specific key value, an obfuscated loader exfiltrates system data via Slack and Telegram and receives command-and-control instructions from a smart contract on the Ethereum Sepolia testnet, complicating takedown. A second-stage payload arrives via X25519 key exchange and AES decryption. The operators maintained a fake GitHub repo with an AI-generated profile image for legitimacy. Checkmarx found nine related malicious packages, all removed, with downloads ranging from hundreds of thousands to over 1.9 million each; the campaign is reported as ongoing. Affected developers should rotate secrets and restore from clean backups.

## Content

A malicious npm package called `indexed-btree` spent roughly 11 weeks on the registry before being removed on September 3, 2026, accumulating nearly 2 million downloads per week. Checkmarx discovered it and reported the campaign, which is described as ongoing.

## What it did

The package impersonated `sorted-btree`, a legitimate B-tree library. Rather than hiding malware in `preinstall` or `postinstall` lifecycle scripts — the hooks that npm and most security scanners watch closely — the attackers embedded their loader inside `BTree.prototype.set()`, a core method that any user of the library would call during normal operation.

This matters because GitHub introduced tighter controls on npm install scripts in June 2026. Those controls don't help if the malicious code lives in a runtime function instead. Static analysis and taint-analysis tools largely missed it too, since the function looked like ordinary library code until it was actually called.

When triggered by a specific key value, the obfuscated loader:

- Fingerprints the host machine
- Exfiltrates system data via Slack and Telegram
- Polls a smart contract on the Sepolia Ethereum testnet to retrieve command-and-control instructions
- Fetches a second-stage payload using X25519 key exchange and AES decryption

Using a blockchain for C2 is a deliberate resilience choice — there's no server to take down.

## Scale and related packages

Checkmarx identified nine additional packages connected to the same campaign, including `btree-core`, which had 1.9 million downloads. Combined downloads across all related packages ran into the millions before npm removed them.

The operators also maintained a fake GitHub repository with an AI-generated profile image to make the project look legitimate.

## What affected developers should do

If you installed any of these packages, rotate any secrets that were accessible in that environment and restore from a known-clean backup. The campaign is still active, so checking your dependency tree for unfamiliar B-tree-related packages is worth doing now.

## Questions this post answers

### How did the indexed-btree npm malware bypass npm's preinstall and postinstall script blocking?

It hid the malicious loader inside BTree.prototype.set(), a core method legitimate users of the sorted-btree-impersonating package would call during normal operation, rather than in an install script. Since GitHub blocked preinstall/postinstall lifecycle scripts in June 2026, static scanners and taint-analysis tools found nothing suspicious at install time because the payload only executes at runtime when triggered by a specific key value.

_Track emerging npm supply chain evasion techniques on daily.dev before they hit your dependency tree._

### How did the indexed-btree malware campaign communicate with its command-and-control infrastructure?

Command-and-control instructions were pulled from a smart contract on the Ethereum Sepolia testnet rather than a traditional server, making takedown considerably harder. Once triggered, the obfuscated loader exfiltrated system details via Slack and Telegram, then fetched a second-stage payload using X25519 key exchange and AES decryption.

_Following novel C2 techniques on daily.dev helps security teams anticipate the next supply chain attack._

### What should I do if I installed the malicious indexed-btree npm package?

Rotate all secrets and restore environments from clean backups. The package impersonated the legitimate sorted-btree library, reached nearly 2 million weekly downloads, and was removed by npm on September 3, 2026, roughly 11 weeks after the first malicious version appeared; Checkmarx also identified nine related malicious packages with similarly high download counts.

_Developers auditing dependencies for supply chain compromises can follow incident updates on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@petermrozek** · 1 upvotes

> More central registries - the supply chain will hold.
>
> As I already said on a few more news like this - there's a gap between the code repository and a central registry - the entity building the package, be it a dev or a CI pipeline. There's absolutely NO GUARANTEE that whatever is in the registry is a carbon copy of the code repository at the time of publishing.
>
> The are only two possible ways to fix this: either central registries start building packages themselves in a controlled environment or we dump central registries altogether in favour of addrsssing the code repos directly with an...

## Similar posts on daily.dev

- [Massive ChainDrop npm supply-chain attack infects hundreds of packages](https://daily.dev/posts/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages-uhzbslfdu) · BleepingComputer · 3 upvotes · 1 comments
- [Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools](https://daily.dev/posts/malicious-npm-package-uses-hidden-prompt-and-script-to-evade-ai-security-tools-l2zvpwytq) · The Hacker News · 1 upvotes · 0 comments
- [jscrambler npm package publishes malicious preinstall binary](https://daily.dev/posts/jscrambler-npm-package-publishes-malicious-preinstall-binary-hv0avwili) · StepSecurity · 2 upvotes · 0 comments
- [Official SAP npm packages compromised to steal credentials](https://daily.dev/posts/official-sap-npm-packages-compromised-to-steal-credentials-c73lsexvg) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#javascript](https://daily.dev/tags/javascript), [#malware](https://daily.dev/tags/malware), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/malicious-npm-package-indexed-btree-bypassed-install-script-defenses-with-runtime-payload-aocxiiqm7)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Malicious npm package 'indexed-btree' bypassed install-script defenses with runtime payload","url":"https://daily.dev/posts/malicious-npm-package-indexed-btree-bypassed-install-script-defenses-with-runtime-payload-aocxiiqm7","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/malicious-npm-package-indexed-btree-bypassed-install-script-defenses-with-runtime-payload-aocxiiqm7"},"datePublished":"2026-09-21T14:28:32.703Z","dateModified":"2026-09-24T11:13:05.222Z","description":"A malicious npm package named indexed-btree impersonated the legitimate sorted-btree library and accumulated nearly 2 million weekly downloads before Checkmarx...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/54fa6ba3c75e6a78327009ab140b3cee?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/54fa6ba3c75e6a78327009ab140b3cee?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/malicious-npm-package-indexed-btree-bypassed-install-script-defenses-with-runtime-payload-aocxiiqm7","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"cyber,javascript,malware,npm","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Malicious npm package 'indexed-btree' bypassed install-script defenses with runtime payload"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/malicious-npm-package-indexed-btree-bypassed-install-script-defenses-with-runtime-payload-aocxiiqm7","comment":[{"@type":"Comment","text":"More central registries - the supply chain will hold.\nAs I already said on a few more news like this - there’s a gap between the code repository and a central registry - the entity building the package, be it a dev or a CI pipeline. There’s absolutely NO GUARANTEE that whatever is in the registry is a carbon copy of the code repository at the time of publishing.\nThe are only two possible ways to fix this: either central registries start building packages themselves in a controlled environment or we dump central registries altogether in favour of addrsssing the code repos directly with an address and tag/commit id. Still not full-proof, but a lot harder to hack and the attack surface is reduced significantly.","datePublished":"2026-09-22T06:56:25.735Z","dateModified":"2026-09-22T06:57:05.668Z","url":"https://daily.dev/posts/AocXIIQm7#c-sA1eF8O5M","author":{"@type":"Person","name":"Peter Mrożek","url":"https://daily.dev/petermrozek","image":"https://media.daily.dev/image/upload/s--pBfYX68K--/f_auto/v1769247960/avatars/avatar_Qz65P1nVw3Bu6C5YwaZgA?_a=BAMAMiiu0"},"interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/malicious-npm-package-indexed-btree-bypassed-install-script-defenses-with-runtime-payload-aocxiiqm7#faq","mainEntity":[{"@type":"Question","name":"How did the indexed-btree npm malware bypass npm's preinstall and postinstall script blocking?","acceptedAnswer":{"@type":"Answer","text":"It hid the malicious loader inside BTree.prototype.set(), a core method legitimate users of the sorted-btree-impersonating package would call during normal operation, rather than in an install script. Since GitHub blocked preinstall/postinstall lifecycle scripts in June 2026, static scanners and taint-analysis tools found nothing suspicious at install time because the payload only executes at runtime when triggered by a specific key value. Track emerging npm supply chain evasion techniques on daily.dev before they hit your dependency tree."}},{"@type":"Question","name":"How did the indexed-btree malware campaign communicate with its command-and-control infrastructure?","acceptedAnswer":{"@type":"Answer","text":"Command-and-control instructions were pulled from a smart contract on the Ethereum Sepolia testnet rather than a traditional server, making takedown considerably harder. Once triggered, the obfuscated loader exfiltrated system details via Slack and Telegram, then fetched a second-stage payload using X25519 key exchange and AES decryption. Following novel C2 techniques on daily.dev helps security teams anticipate the next supply chain attack."}},{"@type":"Question","name":"What should I do if I installed the malicious indexed-btree npm package?","acceptedAnswer":{"@type":"Answer","text":"Rotate all secrets and restore environments from clean backups. The package impersonated the legitimate sorted-btree library, reached nearly 2 million weekly downloads, and was removed by npm on September 3, 2026, roughly 11 weeks after the first malicious version appeared; Checkmarx also identified nine related malicious packages with similarly high download counts. Developers auditing dependencies for supply chain compromises can follow incident updates on daily.dev."}}]}
```

