Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious NPM Package Threatens Supply Chain Security

Malicious NPM Package Threatens Supply Chain Security

Posted on September 22, 2026 By CWS

The NPM ecosystem is facing a significant cybersecurity threat following the discovery of a malicious package that has been downloaded millions of times. According to a report by Checkmarx, the threat actor behind this attack has skillfully evaded recent NPM security measures by embedding a malicious trigger within the package’s JavaScript prototype code.

Innovative Evasion Tactics

Unlike typical attacks that aim for quick spread through high-profile packages, this malicious campaign strategically bypassed detection. The attacker gained trust by setting up a seemingly legitimate GitHub repository, which contributed to the package’s widespread adoption.

The package in question, named indexed-btree, mimics a legitimate tool called sorted-btree. Before detection, it achieved a staggering 2 million downloads weekly, as reported by Checkmarx. The GitHub account supporting this package featured numerous authentic-looking commits, further masking its malicious intent.

Technical Intricacies of the Attack

The hidden threat was embedded in the library’s core functionality, specifically within the BTree.prototype.set method. Upon execution, the embedded malware collected system data and communicated with a hardcoded Slack channel and Telegram chat. It also interacted with a blockchain contract on Sepolia, which served as its command-and-control (C&C) hub, facilitating further malicious activities.

In a previous incident, the attacker’s smart contract surfaced in the mutex-forge package. Overall, the threat actor’s activities have reportedly amassed 109 ETH, equivalent to nearly $300,000.

Wider Implications and Future Outlook

The indexed-btree package is not an isolated case. Other packages linked to this campaign, such as ordered-kv-index and btree-leaderboard, collectively amassed over 5 million downloads before being withdrawn. This ongoing threat poses a dynamic risk to organizations, featuring resilient C&C tactics and deeply concealed malicious code.

Checkmarx warns that such sophisticated attacks underline the necessity for enhanced vigilance and security measures within the software supply chain. As these threats evolve, organizations must prioritize robust security practices to mitigate potential impacts.

Related news highlights similar threats in software supply chains, including targeted attacks on Rust team members and a significant breach affecting 100,000 websites. These incidents collectively emphasize the growing sophistication and scope of supply chain attacks.

Security Week News Tags:Blockchain, Checkmarx, Cryptocurrency, Cybersecurity, GitHub, JavaScript, malicious package, Malware, NPM, supply chain attack

Post navigation

Previous Post: SharePoint Vulnerability Allows Remote Code Execution
Next Post: AI Agents Exploit Retailers, Steal 600,000 Credit Cards

Related Posts

Brightspeed Investigating Cyberattack – SecurityWeek Brightspeed Investigating Cyberattack – SecurityWeek Security Week News
Cisco SD-WAN Exploit Exposed Months Before Patch Cisco SD-WAN Exploit Exposed Months Before Patch Security Week News
Adobe Patches 29 Vulnerabilities – SecurityWeek Adobe Patches 29 Vulnerabilities – SecurityWeek Security Week News
Vibe Coding’s Real Problem Isn’t Bugs—It’s Judgment Vibe Coding’s Real Problem Isn’t Bugs—It’s Judgment Security Week News
OpenAI’s Uncontained AI Sparks Industry Debate OpenAI’s Uncontained AI Sparks Industry Debate Security Week News
Several Code Execution Flaws Patched in Veeam Backup & Replication Several Code Execution Flaws Patched in Veeam Backup & Replication Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit Retailers, Steal 600,000 Credit Cards
  • Malicious NPM Package Threatens Supply Chain Security
  • SharePoint Vulnerability Allows Remote Code Execution
  • Critical SharePoint Flaw Enables Remote Code Execution
  • Cyera Secures $400M, Reaches $12B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark