BlackTree Security · Infrastructure · Automation · AI

This npm Malware Waited Until Runtime to Slip Past Install-Script Defences

Many software-supply-chain controls focus on installation because malicious packages often hide in install hooks. The indexed-btree campaign chose a quieter moment. Its code waited until an application called an ordinary B-tree method, then activated the payload from inside normal runtime behaviour.

Checkmarx says the malicious package impersonated the legitimate sorted-btree library. The trigger was placed inside BTree.prototype.set, a method developers would expect to run during normal data operations. A scanner that only blocked or inspected install scripts could therefore report a clean installation while the dangerous path remained available later.

Runtime was the evasion layer

The campaign targeted developer and application environments, collecting information and sending it through Slack and Telegram. Checkmarx also reports that it used an Ethereum smart contract as resilient command infrastructure. A public blockchain can provide attacker-controlled data without depending on one easily blocked web domain.

The legitimate package that the malware imitated receives nearly two million weekly downloads, according to the research. That does not mean two million hosts installed the malicious copy. Download counts, brand reach and actual compromise are different measurements. The balance of a wallet linked in analysis is also not proof that its funds were stolen through this campaign.

A safe install is not a safe dependency

Install-time policy remains useful. It can stop a large class of package attacks. The failure is treating that one checkpoint as complete. A dependency can execute when it is imported, when a particular method runs, during tests or only after a condition is met.

  • Verify the exact package name. Typos and near-name impersonation are part of the delivery path.
  • Pin and review dependency changes. Require accountable approval for new direct and transitive packages.
  • Scan runtime behaviour. Monitor unexpected network access, child processes and secret discovery from build and application workloads.
  • Restrict CI credentials. A compromised package should not inherit broad publishing, cloud or source-control authority.
  • Search lockfiles and artefacts. Inventory affected versions across active branches, caches, containers and released software.
  • Rotate based on exposure. If the package executed where secrets were readable, remove the dependency, preserve evidence and invalidate the reachable credentials.

The practical lesson is not to abandon install-script controls. It is to extend the trust decision across the dependency’s whole lifecycle. Code that behaves quietly during installation can still become malicious at the first ordinary function call.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *