Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
Sep 22, 2026
Supply Chain Attack / Malware
A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls . "Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility," Checkmarx said . "Unlike the common attacks we've seen in the supply chain space, this package does not rely on preinstall / postinstall at all. Instead, it runs entirely from application code at runtime." The package and the associated GitHub repository are no longer available for download from npm. However, statistics show the package was first uploaded to the registry on June 18, 2026, by an npm user named " charlessadler25 ," amassing millions of downloads in a short span of time . To make matters worse, the campaign may have generated illicit profits for the...