# Malicious npm package hides malware in runtime behavior

_Published Sunday, September 20, 2026 at 12:07 PM EDT · Security · Latest · Tier 1 — Major_

![Malicious npm package hides malware in runtime behavior — Primary](https://www.bleepstatic.com/content/hl-images/2026/05/15/npm.jpg)

Checkmarx researchers identified an ongoing npm malware campaign using the package indexed-btree, which impersonates the legitimate sorted-btree library. The package avoids install scripts and instead triggers a loader through its runtime BTree.prototype.set method, bypassing npm v12's install-time approval controls. BleepingComputer reports that Checkmarx linked nine additional packages to the operation and that npm removed them. The malware can collect system details and retrieve a second-stage payload.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/)

---
Canonical: https://techandbusiness.org/newswire/ELN2AOIoNNWB6LFH8pOLR3
Published: 2026-09-20T16:07:36.810Z
Story chronology: 2026-09-20T14:11:21.000Z
Retrieved: 2026-09-20T17:58:24.046Z
Publisher: Tech & Business (techandbusiness.org)
