Malicious npm packages with millions of downloads slip past install-time defences
Checkmarx researchers have uncovered a campaign of malicious packages on npm, the largest JavaScript library registry, led by indexed-btree, a package that impersonates the legitimate sorted-btree library and racks up around two million weekly downloads. The campaign includes at least nine packages, such as btree-core, btree-leaderboard and priority-slot-queue, each with hundreds of thousands of downloads. Its main novelty is how it hides: the malicious code is not in the scripts that run when the package is installed but inside a function that only activates when the application uses it.
This way it gets around the measures GitHub introduced in npm in June 2026 to block install scripts. Once active, the malware collects system information, sends it through Slack and Telegram channels, receives commands via an Ethereum smart contract and can erase its own traces. Security expert Bruce Schneier describes it as an impressive piece of malware whose sophistication suggests a nation-state to him, although there is no direct evidence or attribution.
Tip from Soporte Informático 360
If your company develops software, don’t rely only on scanning packages at install time: add runtime behavioural analysis and check dependency names carefully before adding them. If you have used any of these packages, rotate credentials and secrets and restore from a safe backup.
Source: BleepingComputer. Summary prepared by our team for informational purposes.
IT maintenance for businesses
Preventive and corrective maintenance of your equipment to avoid downtime and extend its useful life.