Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Package Conceals Code in Runtime

Malicious npm Package Conceals Code in Runtime

Posted on September 22, 2026 By CWS

A recent discovery has revealed that a malicious npm package, indexed-btree, cleverly concealed its harmful actions within application runtime code. This tactic marks a shift in strategy by cybercriminals, who are adapting to new security measures that limit lifecycle script exploitation.

New Tactics in Malware Distribution

The indexed-btree package mimicked a legitimate utility, sorted-btree, to infiltrate systems. Unlike previous attacks, which exploited install scripts, this package relied solely on runtime execution. The change comes in response to npm’s updated security protocols that block automatic script execution during installation.

Initially uploaded in June 2026 by user charlessadler25, the package quickly gained traction, accumulating millions of downloads. The operation reportedly netted the attackers nearly €230,933.57 in cryptocurrency, highlighting the financial motive behind the campaign.

Technical Details of the Attack

Checkmarx, a software security firm, identified that the malicious code was embedded in the BTree.prototype.set() method, activating a payload from sharedLoad.min.js. This script executed various malicious activities, including system fingerprinting and data transmission to external platforms like Slack and Telegram.

Furthermore, the malware utilized the EtherHiding technique to download encrypted data blobs from a blockchain smart contract, eventually compiling them into a secondary payload. This sophisticated maneuver demonstrates the attackers’ advanced capabilities in circumventing traditional security measures.

Broader Implications and Defense Strategies

The discovery of indexed-btree illustrates a broader shift in threat actor tactics. As attackers develop new methods to bypass security, defenders must enhance their strategies. Experts advise implementing runtime behavior analysis in addition to traditional install-time scanning to detect and mitigate threats.

Ensar Seker, CISO at SOCRadar, emphasizes the importance of layered security controls, noting that attackers continually adapt to changes. While blocking lifecycle scripts is beneficial, additional measures are necessary to identify and stop malicious activities at every stage.

PolinRider: A Parallel Threat

In a related development, a malicious campaign dubbed PolinRider has been identified on Packagist. The campaign involves compromising developer accounts to inject harmful code into repositories. This method leverages routine developer actions as triggers, further complicating detection efforts.

Security researcher Karlo Zanki reported that the compromised Visanduma GitHub organization has been affected since mid-June 2026. The attack employed obfuscated JavaScript executed via PHP, showcasing the adaptability of threat actors in targeting development environments.

The ongoing threat landscape underscores the need for comprehensive security measures that address both pre-installation and runtime threats. As attackers continue to evolve, the software community must remain vigilant and proactive in defending against these sophisticated attacks.

The Hacker News Tags:Blockchain, Checkmarx, crypto theft, Cybersecurity, EtherHiding, GitHub, JavaScript, malicious code, NPM, PolinRider, runtime code, Security, software defense, supply chain attack

Post navigation

Previous Post: Windows Vulnerability Exploited Through Malicious DLLs
Next Post: Critical Vulnerability Found in D-Link Router

Related Posts

Critical MetInfo CMS Flaw Exploited for Code Execution Critical MetInfo CMS Flaw Exploited for Code Execution The Hacker News
Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access The Hacker News
Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security The Hacker News
Hades Attack Targets PyPI: 19 Packages Compromised Hades Attack Targets PyPI: 19 Packages Compromised The Hacker News
Azure Cosmos DB Vulnerability Could Access Databases Azure Cosmos DB Vulnerability Could Access Databases The Hacker News
FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Researcher Reveals New Microsoft Defender Exploit
  • AI Agents Redefine Lateral Movement in Security
  • Hackers Use Fake Websites for Chrome and Windows Exploits
  • OT Network Segmentation Lacks Full Isolation: Study
  • DORA’s Impact on SOC Visibility: Key Insights

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Researcher Reveals New Microsoft Defender Exploit
  • AI Agents Redefine Lateral Movement in Security
  • Hackers Use Fake Websites for Chrome and Windows Exploits
  • OT Network Segmentation Lacks Full Isolation: Study
  • DORA’s Impact on SOC Visibility: Key Insights

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark