{"id":5117,"date":"2026-09-22T17:10:06","date_gmt":"2026-09-22T17:10:06","guid":{"rendered":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/22\/new-npm-threat-bypasses-install-script-protections\/"},"modified":"2026-09-22T17:10:06","modified_gmt":"2026-09-22T17:10:06","slug":"new-npm-threat-bypasses-install-script-protections","status":"publish","type":"post","link":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/2026\/09\/22\/new-npm-threat-bypasses-install-script-protections\/","title":{"rendered":"New npm Threat Bypasses Install Script Protections"},"content":{"rendered":"<div><img data-opt-id=166840461  fetchpriority=\"high\" decoding=\"async\" width=\"770\" height=\"330\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/06\/npm_v12_supply_chain_security_770x330.jpg\" class=\"attachment-large size-large wp-post-image\" alt=\"\" \/><\/div>\n<p><img data-opt-id=1621358267  fetchpriority=\"high\" decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/devops.com\/wp-content\/uploads\/2026\/06\/npm_v12_supply_chain_security_770x330-150x150.jpg\" class=\"attachment-thumbnail size-thumbnail wp-post-image\" alt=\"\" \/><\/p>\n<p>A malicious npm package that has been downloaded millions of times comes with a new way of spreading the malware that makes it easier to bypass security protections, say researchers with security vendor Checkmarx.<\/p>\n<p>Rather than using more common preinstall or postinstall scripts, the bad actors instead created a malicious package \u2013 indexed-btree \u2013 that mimics the legitimate sorted-btree package and hides the malware in the package\u2019s runtime code, according to Checkmarx security researcher Bruno Dias.<\/p>\n<p>Indexed-btree \u201cruns entirely from application code at runtime,\u201d Dias <a href=\"https:\/\/checkmarx.com\/zero-post\/npm-btree-malware-campaign-affects-millions-of-downloads-no-need-for-install-script\/\" target=\"_blank\" rel=\"noopener\">wrote in a report<\/a>. \u201cAdditionally, this package achieved almost 2 million weekly downloads, which shows not much has changed in the npm ecosystem despite the limitations put on lifecycle scripts.\u201d<\/p>\n<p>The latest <a href=\"https:\/\/devops.com\/fast-moving-shai-hulud-attack-infects-npm-packages-with-2-billion-monthly-downloads\/\">malware targeting npm packages<\/a> hides inside the Btree.prototype.set, the standard method in JavaScript B-Tree data structures. Because there\u2019s no install hook inside the package.json file, installing the package does not launch any malicious activity. However, using the package can trigger the JavaScript code that includes the malware\u2019s first stage.<\/p>\n<p>The malicious package includes a heavily obfuscated file that includes a range of tasks, including fingerprinting and exfiltrating such host information as the operating system architecture, hostname, the CPU, and memory, which are then sent to a hardcoded Slack channel and Telegram chat.<\/p>\n<p>It also uses an Ethereum smart contract on Sepolia testnet \u2013 a proof-of-stake (PoS) testnet that developers use to deploy and test smart contracts \u2013 as its command-and-control (C2) channel. The testnet <strong>\u201c<\/strong>exposes getter and setter functions that the malware polls instead of requesting a plain domain,\u201d Dias wrote, adding that the technique \u201cis more resilient to domain [or] IP takedown than traditional C2 approaches, since it uses the smart contract as a pointer to a new address whenever the old one gets taken down.\u201d<\/p>\n<p>The malicious code includes the ability to delete its malware files and remove the trigger code to erase its traces.<\/p>\n<h3>Attacker Creates a GitHub Repository<\/h3>\n<p>Along with the decision to hide the malicious code by mimicking a legitimate package, the attacker also includes a seemingly <a href=\"https:\/\/devops.com\/how-github-plans-to-secure-npm-after-recent-supply-chain-attacks\/\" target=\"_blank\" rel=\"noopener\">legitimate GitHub repository<\/a> that comes with realistic commits and an account. As of late last week, the repository was still up and the attack was ongoing, according to Checkmarx.<\/p>\n<p>\u201cA GitHub repository is something that attackers don\u2019t usually bother creating,\u201d Dias wrote. \u201cThis one is clever enough to not include the malicious code. Additionally, the presence of many commits can aid in making it look like a legit repository.\u201d<\/p>\n<p>In addition, while there is not much in the account in terms of activity or an in-depth bio, it does include an AI-generated photo, which is another way of giving the repository an air of legitimacy.<\/p>\n<p>Checkmarx estimates that the bad actor was able to collect 109 ETH, or about $264,963.<\/p>\n<h3>Adapting to Defenses<\/h3>\n<p>\u201cWhat makes this campaign particularly important is that it shows attackers adapting almost immediately to stronger software supply chain defenses,\u201d SOCRadar CISO Ensar Seker said. \u201cnpm has improved install time security by restricting dependency lifecycle scripts, but this campaign demonstrates that attackers can simply move malicious execution into legitimate looking runtime functionality instead.\u201d<\/p>\n<p>A clean installation no longer leads to a clean dependency, Seker said, adding that <a href=\"https:\/\/devops.com\/flooding-dropper-is-hitting-npm-with-a-tidal-wave-of-malicious-packages\/\">software supply chain security<\/a> now needs to extend beyond the reputation of a package and installation-time scanning. Defenders need to look at such areas as dependency provenance, unexpected code changes, runtime behavior, and outbound network connections.<\/p>\n<p>\u201cThe broader lesson is that security controls change attacker behavior rather than eliminate the underlying threat,\u201d he said.<\/p>\n<p><a href=\"https:\/\/devops.com\/new-npm-threat-bypasses-install-script-protections\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\">Read More<\/a><\/p>\n<p>\u200b<\/p>","protected":false},"excerpt":{"rendered":"<p>A malicious npm package that has been downloaded millions of times comes with a new way of spreading the malware [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5118,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-5117","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops"],"_links":{"self":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/comments?post=5117"}],"version-history":[{"count":0,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/posts\/5117\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media\/5118"}],"wp:attachment":[{"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/media?parent=5117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/categories?post=5117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rssfeedtelegrambot.bnaya.co.il\/index.php\/wp-json\/wp\/v2\/tags?post=5117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}