A malicious npm package called "indexed-btree" employed runtime code injection to evade detection mechanisms, hiding its malicious behavior directly within application execution rather than relying on installation scripts.
The package mimicked the legitimate "sorted-btree" library, a B-tree indexing utility commonly used in Node.js applications. Checkmarx researchers discovered that the threat actors behind "indexed-btree" embedded their payload within the package's runtime code instead of using npm lifecycle scripts like preinstall or postinstall hooks. This represents a tactical shift designed to bypass recent security improvements targeting script-based supply chain attacks.
Traditional npm attacks rely on lifecycle scripts that execute during package installation, making them visible to security scanning tools and package managers that have hardened defenses around these hooks. By hiding malicious behavior within the actual application code, attackers reduce the window for detection. The payload executes only when the application calls the package's functions, creating a timing gap between installation and activation that many security systems miss.
The "indexed-btree" package demonstrates the evolving sophistication of npm ecosystem threats. Developers installing what appears to be a legitimate utility may not notice malicious code executed deep within the package's dependency chain. This attack method bypasses common static analysis tools that scan installation scripts but may not thoroughly inspect runtime behavior embedded in compiled or obfuscated code.
npm packages remain a critical attack surface. The ecosystem contains millions of packages maintained by individual developers with varying security practices. Typosquatting campaigns (using names similar to popular packages) combined with runtime code injection create a compounded risk. Developers searching for "sorted-btree" might miss the difference and install "indexed-btree" instead, especially under time pressure or in automated dependency updates.
Once embedded, the malicious code could perform various attacks. Common objectives include credential theft, process injection, data exfiltration, or establishing persistence mechanisms. Supply chain infections at the package level spread the threat across all downstream users, potentially affecting thousands of applications and millions of end users.
Checkmarx's discovery highlights the need for expanded security practices beyond script monitoring. Organizations should implement runtime behavior analysis, require code review processes for third-party dependencies, and use Software Bill of Materials (SBOM) tools to track package contents. The npm Security team removed "indexed-btree" from the registry after discovery, but similar packages may already exist or be created.
Developers using npm should verify package authenticity by checking download counts, GitHub repository links, maintenance history, and developer reputation. Typo-prevention tools and package pinning to specific versions reduce exposure to new malicious packages. Supply chain security requires layered defenses because no single control catches every threat.
The shift from lifecycle script attacks to runtime code injection reflects threat actor adaptation to improved platform security. As defenders deploy new controls, attackers develop countermeasures. This escalating cycle demands continuous monitoring, threat intelligence, and evolved detection strategies focused on behavioral analysis rather than static script detection alone.
