A malicious npm package named 'indexed-btree' has been discovered hiding its harmful activities within application code, marking a shift in strategy among threat actors in response to new security measures. The package impersonated the legitimate 'sorted-btree' utility and bypassed the usual lifecycle scripts like preinstall or postinstall, executing its malicious code at runtime instead. This package, uploaded by a user named 'charlessadler25' on June 18, 2026, amassed millions of downloads before it and its associated GitHub repository were removed from npm. The campaign reportedly netted its operators around €230,933.57 in cryptocurrency, underscoring the financial motivations behind such attacks.

Npm's version 12 introduced changes to prevent automatic execution of lifecycle scripts, a common malware vector, but attackers adapted by embedding malicious code directly into runtime functionality. In this case, the malware loader was hidden inside a method that triggered a JavaScript payload, which then executed a series of actions designed to fingerprint the host, communicate with hard-coded Slack and Telegram channels, and use blockchain-based techniques to deploy further stages of the malware.

The discovery highlights the need for developers to go beyond install-time scanning and incorporate runtime behavior analysis to detect such threats. Checkmarx emphasized that while blocking lifecycle scripts is a vital security measure, attackers will continue to find new paths for malicious execution, necessitating robust, layered security controls.

In a related incident, Socket reported the removal of malicious code from the 'visanduma/nova-two-factor' package on Packagist, part of a broader campaign linked to North Korea and dubbed PolinRider. This campaign exploits developer accounts to inject malware into source code repositories, using routine actions to trigger infections and employing advanced techniques like EtherHiding for resilient payload delivery. The attackers demonstrated a flexible approach by adapting their methods based on compromised projects, further complicating detection and mitigation efforts.