Malicious npm Package Bypasses Install-Script Security Controls

· Original article ↗

Summary

Researchers report an ongoing npm supply-chain campaign using the malicious indexed-btree package, which activates when an application uses it, bypassing npm’s default blocking of dependency install scripts.

Key points

  • The malicious indexed-btree package mimics the legitimate sorted-btree library and hides its trigger in a prototype method, activating when the application uses the library rather than during installation.
  • Once active, the malware fingerprints hosts, exfiltrates data via Slack and Telegram, and uses an Ethereum smart contract for command and control.
  • The package has a clean package.json and is backed by a fake-looking GitHub repository and developer profile, undermining checks based on install hooks or public source code.
  • Researchers say the campaign is ongoing, its command-and-control infrastructure remains active, and it is not limited to btree packages.
  • Organizations that used affected packages should determine where they were present and whether they ran, investigate for suspicious activity and exposed credentials or secrets, and rebuild affected environments from trusted sources where needed.
  • The report recommends looking beyond install-time checks to package validation, malicious-package intelligence, runtime behavior monitoring, and binary analysis.

Article Details

Event Type
Ongoing npm software supply chain attack using a malicious dependency that activates when its library code runs, bypassing npm's default restriction on install scripts.
Impact
The malicious indexed-btree package can execute with the application's permissions and network access. The article reports host fingerprinting and data exfiltration via Slack and Telegram; it does not quantify affected systems or confirmed credential exposure.

MITRE ATT&CK

People

Products

Related Articles