Malicious npm Package indexed-btree Hid Code Until Runtime
A Checkmarx analysis uncovered the indexed-btree npm package, which imitated a legitimate library and activated a malicious loader during application runtime.

The malicious indexed-btree npm package hid a malicious loader directly in the library code rather than in installation scripts. Checkmarx published its analysis on September 17, 2026, stating that the package imitated the legitimate sorted-btree project.
The case highlights a risk in the JavaScript supply chain: dependency checks focused only on preinstall and postinstall scripts may not detect similar behavior. The malicious activity was reportedly triggered only during normal use of the library in an application.
The malicious indexed-btree npm package in runtime code
Checkmarx said the loader was inserted into the BTree.prototype.set method. This is part of the tree data structure implementation, meaning the malicious code did not rely on automatic execution during package installation.
According to the analysis, the loader activated only after a specific condition was met during application runtime. It then collected information about the host system. Checkmarx described data exfiltration through Telegram and Slack, as well as the use of a smart contract on the Ethereum Sepolia network as a C2 communication channel, meaning infrastructure for controlling malicious code.
Researchers linked the operation to nine other npm packages. According to Checkmarx, they were subsequently removed. Snyk lists all versions of indexed-btree as malicious and says the package contents were removed from the official npm registry.
Why a runtime trigger complicates dependency checks
npm installation scripts are among the common areas reviewed by security tools and developers because they can execute arbitrary commands while a dependency is being added. In this case, however, Checkmarx did not identify the use of preinstall or postinstall scripts.
The malicious indexed-btree npm package therefore posed a risk only when the application called the affected function and the loader’s conditions were met. The absence of a lifecycle script alone is not confirmation that an npm dependency is safe.
What has not been confirmed so far
In its analysis, Checkmarx pointed to a high number of downloads, but this figure does not establish the number of systems on which the package was actually run or the number of compromised environments. The extent of successful exploitation is therefore unknown.
It has also not been independently confirmed that the 109 ETH in the identified cryptocurrency wallet is connected to this campaign or to cryptocurrency thefts. The identity and motivation of the actors remain unknown.
What developers should check
Projects that used indexed-btree or packages associated with the operation should review their dependency manifests and lock files, remove the affected dependencies, and assess whether code using the relevant library functions was executed in their environments. Reviewing available indicators of compromise and network communications related to the described C2 channels is also relevant.
Further findings may come from confirmations by npm or GitHub about the scope of the package removals, new indicators of compromise, and Checkmarx updates on the C2 infrastructure or the malware’s second stage.
Sources
- Checkmarx Zero – Initial technical analysis of indexed-btree, the runtime trigger, exfiltration, C2, and the list of related packages.
- Snyk – Listing of indexed-btree as a malicious package and information that its contents were removed from the official registry.
- BleepingComputer – Independent summary of Checkmarx’s findings and a warning that the download count is not direct evidence of compromise.
Verified and updated: September 22, 2026 15:25



