Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Package Evades Detection with Runtime Activation

Malicious npm Package Evades Detection with Runtime Activation

Posted on September 21, 2026 By CWS

A recent cybersecurity threat has emerged from a seemingly innocuous npm package, revealing vulnerabilities in software supply-chain protections. The malicious package, named indexed-btree, masquerades as a legitimate tool while hiding harmful code that only activates during runtime.

Disguised Threat in npm Package

The indexed-btree package, which deceptively copied the identity of the legitimate sorted-btree library, has been downloaded nearly two million times weekly. Unlike typical malware that activates during installation, this malicious code remains dormant until triggered during runtime, posing significant risks to unsuspecting developers. Researchers from Checkmarx were the first to uncover this dangerous campaign.

Checkmarx’s findings, shared with Cyber Security News, highlight the limitations of current security checks that focus solely on installation scripts. The package’s ability to integrate seamlessly into regular development processes underscores the need for more comprehensive security measures.

Technical Mechanisms of the Attack

The absence of preinstall or postinstall commands in indexed-btree’s configuration allows it to evade initial detection. The malicious code is embedded within BTree.prototype.set, a core method frequently used during data storage operations in applications. When activated, this code executes an obfuscated first-stage component that collects system information and communicates with attacker-controlled networks.

This operation uses a smart contract on the Ethereum Sepolia test network instead of traditional command servers, complicating disruption efforts. The malware further secures its operations with cryptographic key exchanges, ensuring continued functionality even if original command addresses are blocked.

Additionally, the package includes mechanisms to remove malware traces and deactivate triggers, complicating detection and forensic analysis post-activation.

Recommendations for Strengthening Security

The incident underscores a critical gap in current software supply-chain defenses, particularly when lifecycle scripts are absent. Organizations are advised to scrutinize all package names and versions within their systems, removing any suspect entries and rotating compromised credentials.

Security teams should conduct comprehensive reviews of package ownership, release histories, and repository consistency. Running potentially harmful packages in isolated environments and monitoring runtime behaviors can reveal hidden threats that static scans may miss.

Developers are encouraged to lock verified dependency versions, maintain updated software bills of materials, and scrutinize any new or altered packages before approval. This approach aims to mitigate risks associated with backdoored npm packages and configuration abuses.

As this campaign continues, immediate actions should focus on determining whether the malicious library was merely downloaded or actively executed in systems. Runtime evidence and network telemetry offer the most reliable insights for ongoing threat assessments.

Cyber Security News Tags:blockchain command-and-control, Checkmarx, Cybersecurity, data theft, host profiling, indexing tool, malicious packages, npm security, runtime activation, software supply chain

Post navigation

Previous Post: Massive Data Loss in 103 Seconds by AI Coding Agent
Next Post: North Korea’s VPN Infrastructure Exposed by TLS Certificate

Related Posts

Windows Admin Center Vulnerability (CVE-2025-64669) Let Attackers Escalate Privileges Windows Admin Center Vulnerability (CVE-2025-64669) Let Attackers Escalate Privileges Cyber Security News
Claude Mythos 5 Enhances Security with AI Vulnerability Scans Claude Mythos 5 Enhances Security with AI Vulnerability Scans Cyber Security News
Ivanti EPMM Vulnerabilities Threaten Global Networks Ivanti EPMM Vulnerabilities Threaten Global Networks Cyber Security News
Chinese Hackers Using Custom ShadowPad IIS Listener Module to Turn Compromised Servers into Active Nodes Chinese Hackers Using Custom ShadowPad IIS Listener Module to Turn Compromised Servers into Active Nodes Cyber Security News
Threat Actors Attacking Gen Z Gamers With Weaponized Versions of Popular Games Threat Actors Attacking Gen Z Gamers With Weaponized Versions of Popular Games Cyber Security News
Upcoming DMARC Enhancements Discussed by Email Experts Upcoming DMARC Enhancements Discussed by Email Experts Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korea’s VPN Infrastructure Exposed by TLS Certificate
  • Malicious npm Package Evades Detection with Runtime Activation
  • Massive Data Loss in 103 Seconds by AI Coding Agent
  • Google Fined €403M for GDPR Breaches in Location Data
  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korea’s VPN Infrastructure Exposed by TLS Certificate
  • Malicious npm Package Evades Detection with Runtime Activation
  • Massive Data Loss in 103 Seconds by AI Coding Agent
  • Google Fined €403M for GDPR Breaches in Location Data
  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark