Malicious npm packages evade install-script defenses at runtime

Executive Summary

Threat actors are using the npm package 'indexed-btree' to hide malicious code in its normal runtime behavior, bypassing install‑script defenses. The campaign demonstrates how supply‑chain attacks can evade traditional security controls by embedding malware in the package’s runtime rather than during installation. Security teams should monitor runtime activity and review package provenance to detect similar threats.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-20T14:11:21+00:00 - Category: threat-intel

Original Description: An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

"To accomplish great things, we must dream as well as act."

— Anatole France
Source: Bleeping Computer