A counterfeit npm package, indexed-btree, impersonated the legitimate sorted-btree library and embedded malicious logic in BTree.prototype.set() rather than using install-time lifecycle hooks. The payload activated during ordinary application use when a key equal to 100 was inserted and extended/sharedLoad.min.js was present, allowing it to evade npm v12 controls designed to require approval for lifecycle scripts.
The obfuscated loader fingerprinted affected hosts and exfiltrated reconnaissance to hard-coded Slack and Telegram endpoints. It used an Ethereum Sepolia testnet smart contract for resilient command-and-control and encrypted second-stage payload delivery, deriving AES keys through X25519/ECDH; it also removed injected code and malicious files to reduce forensic evidence. Checkmarx linked the activity to nine additional removed packages and the earlier mutex-forge package through shared blockchain infrastructure; the associated packages had millions of downloads, and operators reportedly accumulated 109 ETH through the smart contract.

Trace attribution and downstream blast radius.
3 events from the most recent confirmed update back to the earliest known activity.
Checkmarx Zero published analysis of a campaign in which counterfeit indexed-btree impersonated sorted-btree and executed an obfuscated loader through BTree.prototype.set() during normal runtime use, bypassing npm v12 lifecycle-script controls. The analysis linked the campaign to nine additional packages and described Slack/Telegram exfiltration, Ethereum Sepolia smart-contract C2, encrypted second-stage delivery, and self-erasure behavior.
Snyk published an advisory identifying all versions of the npm package indexed-btree as malicious under CWE-506. The affected published versions were reported as 2.1.1 through 2.1.3.
Following disclosure, the npm registry replaced indexed-btree with a 0.0.1-security holding stub.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.