Malicious npm Packages Evade Install-Script Defenses at Runtime
Campaign involving 'indexed-btree' and similar packages bypasses traditional supply chain security controls

Key Takeaways
- Malicious npm packages are evading install-script defenses by executing malicious code during normal runtime rather than during installation.
- The 'indexed-btree' package is one example of this evasion technique observed in the wild.
- Developer systems and downstream applications that use these compromised packages are at risk of data theft or further malware deployment.
- Defensive recommendations include auditing dependencies, removing affected packages, and awaiting official patches or advisories from npm.
Quick answers
- What happened?
- Security researchers have identified a campaign of malicious npm packages that evade standard supply chain defenses by concealing harmful code within normal runtime execution rather than installation scripts. The 'indexed-btree' package is among those observed employing this technique, raising concerns for developer environments relying on automated dependency scanning.
- Which products are affected?
- npm
- What should defenders do?
- Remove affected npm packages from projects, audit all dependencies for suspicious code, and monitor official npm security advisories and updates for this campaign.
A ongoing npm malware campaign has been documented by BleepingComputer, involving packages such as 'indexed-btree' that bypass conventional supply chain defenses. Rather than embedding malicious payloads in install scripts—which are commonly monitored by security tools—the threat actors have designed the malicious code to execute during the package's normal runtime behavior. This approach allows the malware to evade defenses that specifically audit installation hooks and scripts. Packages exhibiting this runtime evasion technique have been found in the npm registry, and their use could lead to compromise of developer systems and any downstream applications that depend on them. The exact scope of the campaign, the full list of affected packages, and specific technical details of the malicious payload remain limited based on initial reporting. Security authorities recommend that developers audit their dependencies, remove any suspicious packages, and monitor for official advisories or updates from npm regarding this campaign.
Security Details
The malicious code in observed packages executes during normal runtime behavior, bypassing security controls that monitor only install scripts. Specific payloads, CVE identifiers, and exploitation vectors have not been confirmed in the initial report.
Affected products
npm
Mitigation
Remove affected npm packages from projects, audit all dependencies for suspicious code, and monitor official npm security advisories and updates for this campaign.
Sources
BleepingComputer
Malicious npm packages evade install-script defenses at runtime
Sep 20, 2026 · 14:11
Original link
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




