Skip to content
Back to the blog
Supply chain September 24, 2026 · 1 min read

Malicious npm packages with millions of downloads slip past install-time defences

Checkmarx researchers have uncovered a campaign of malicious packages on npm, the largest JavaScript library registry, led by indexed-btree, a package that impersonates the legitimate sorted-btree library and racks up around two million weekly downloads. The campaign includes at least nine packages, such as btree-core, btree-leaderboard and priority-slot-queue, each with hundreds of thousands of downloads. Its main novelty is how it hides: the malicious code is not in the scripts that run when the package is installed but inside a function that only activates when the application uses it.

This way it gets around the measures GitHub introduced in npm in June 2026 to block install scripts. Once active, the malware collects system information, sends it through Slack and Telegram channels, receives commands via an Ethereum smart contract and can erase its own traces. Security expert Bruce Schneier describes it as an impressive piece of malware whose sophistication suggests a nation-state to him, although there is no direct evidence or attribution.

Tip from Soporte Informático 360

If your company develops software, don’t rely only on scanning packages at install time: add runtime behavioural analysis and check dependency names carefully before adding them. If you have used any of these packages, rotate credentials and secrets and restore from a safe backup.

Source: BleepingComputer. Summary prepared by our team for informational purposes.

Related service

IT maintenance for businesses

Preventive and corrective maintenance of your equipment to avoid downtime and extend its useful life.