What happened
The npm package indexed-btree pretended to be the legitimate sorted-btree library while secretly running malicious code at runtime. The package alone accounts for about two million weekly downloads, giving the attackers a broad foothold.
Why it matters
GitHub’s June 2026 security update blocks most install‑script hooks unless they are explicitly approved. The indexed-btree loader sidesteps that protection by embedding its payload inside the BTree.prototype.set() method, which only executes when the library is used.
Technical breakdown
When an application calls set(), the code collects architecture, hostname, CPU, memory and uptime. Those details are posted to hard‑coded Slack and Telegram channels. At the same time the malware polls a smart contract on the Sepolia test network for command‑and‑control (C2) instructions.
The contract stores an encrypted second‑stage payload. The malware performs an X25519 key exchange, derives an AES key, decrypts the payload and executes it. Operators can later send a command that erases the malicious files and strips the trigger code from the package.
Related packages
Checkmarx found nine more packages that followed the same pattern. All have been removed from npm.
- ordered‑kv‑index – 448,184 weekly downloads
- btree‑leaderboard – 493,685 weekly downloads
- priority‑slot‑queue – 402,860 weekly downloads
- btree‑range‑store – 468,092 weekly downloads
- btree‑core – 1,951,274 weekly downloads
- btree‑time‑index – 425,312 weekly downloads
- btree‑lru‑cache – 372,185 weekly downloads
- neighbor‑key‑map – 366,019 weekly downloads
- sliding‑score‑window – 448,024 weekly downloads
Who is at risk
Any project that installed indexed-btree or the nine related packages is potentially compromised. Because the payload runs only when the library is invoked, even downstream dependencies that indirectly pull the package are exposed.
Defensive steps
- Audit your dependency tree for
indexed-btreeand the nine listed packages. - If found, remove the packages and reinstall clean versions of your dependencies.
- Rotate every secret, token or API key that may have been exposed.
- Restore affected environments from backups taken before the packages were installed.
- Enable npm v12’s approval mechanism for lifecycle scripts and only whitelist scripts you have reviewed.
- Monitor outbound traffic for unexpected calls to Slack, Telegram or Ethereum nodes.
