checkmarx.com Npm Btree Malware Campaign Evades Security Measures
Article Content
- •The 'indexed-btree' package bypasses npm's security by hiding malware in runtime code.
- •Attackers have earned approximately €230,933.57 from this campaign using Ethereum.
- •Checkmarx identified nine additional malicious npm packages linked to this operation.
A malicious npm package named 'indexed-btree' is part of an ongoing supply chain attack, affecting millions of downloads. This package mimics the legitimate 'sorted-btree' library and has achieved nearly 2 million weekly downloads. Instead of using traditional install scripts, the malware is activated through the package's BTree.prototype.set method during runtime. The attackers have reportedly earned 109 ETH, approximately €230,933.57, from this campaign. The malware collects system information and exfiltrates it via hardcoded Slack and Telegram channels. Security measures introduced by GitHub in June 2026, aimed at blocking lifecycle scripts, have been bypassed by this method. Checkmarx has identified nine additional npm packages linked to the same operation, which have also garnered significant downloads. The campaign is ongoing, and further updates are expected as more details emerge.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Btree-core and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…