Indexed-btree linked npm malware campaign
Campaign
Updated: 20.09.2026 17:11
· First: 20.09.2026 17:11
· 📰 1 src / 1 articles
· H score: 26
The indexed-btree npm malware campaign expanded to nine additional packages linked to the same operation, widening exposure across the npm ecosystem. The packages impersonated sorted-btree and used runtime execution to bypass npm v12 install-script defenses, putting developers at risk of hidden code execution. The malware could collect host details, exfiltrate them through Slack and Telegram, and use a Sepolia smart contract for command and control.