- Sources: primary
- Summary: Checkmarx reports that
indexed-btree impersonates the legitimate sorted-btree library with a fabricated commit history and a curated developer account, and that it reached 2 million weekly downloads. The loader sits inside the library's own BTree.prototype.set() method and executes at runtime when the application calls it with a specific key value, so no install script runs. Once triggered it collects architecture, hostname, CPU, memory, and uptime, exfiltrates through hardcoded Slack and Telegram channels, and polls an Ethereum Sepolia smart contract for command and control, using an X25519 key exchange to derive an AES key for a second-stage payload, and it can delete its files and remove the trigger to wipe traces. Checkmarx found nine further linked packages, now removed from npm: btree-core (1,951,274 downloads), btree-leaderboard (493,685), btree-range-store (468,092), ordered-kv-index (448,184), sliding-score-window (448,024), btree-time-index (425,312), priority-slot-queue (402,860), btree-lru-cache (372,185), and neighbor-key-map (366,019). The reporting names no affected version ranges for indexed-btree or the nine linked packages, so the stated remediation, that anyone who installed any of them rotates all secrets and restores the development environment from a safe backup, applies to any installed version. - Why it matters: The placement defeats the lifecycle-script approval npm shipped in June 2026, so install-time scanning alone no longer establishes that a dependency is clean.
- Follow-up: Whether npm or the major scanners add runtime-path analysis.
send feedback on this story