# Malicious npm packages move execution from install hooks into runtime code

_Published Tuesday, September 22, 2026 at 8:08 AM EDT · Security · Latest · Tier 1 — Major_

![Malicious npm packages move execution from install hooks into runtime code — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaN7aXt0PoPdZQ_VG77wkwdIyNugcdkFD6MnMvlj5LN_byw2ZrX8-gtpDld4CviuW1MOhHiElsvFtIkO9IfhBr4af-sJwM1zvR-RFICRll4G5jG4JNPX1vx4sup3omlw8uTJgro9UUfzecLMI1Whls3ihqZ9OXYJliIBjhpoodf4WI9j1lA6EUjms7x1pG/s1700-nu-rw-lo-l85-e365/rth.jpg)

Researchers found a malicious npm package called indexed-btree that concealed its loader inside an ordinary runtime method, bypassing defenses focused on installation scripts. The package, which mimicked sorted-btree, triggered an obfuscated payload when its B-tree set method ran, fingerprinted the host and contacted Slack and Telegram infrastructure.

The malware then retrieved encrypted stages from a smart contract on the Sepolia test network and deleted artifacts to hide its activity. Indexed-btree and ten other packages tied to the operation have been removed from npm. Download counts and an estimate of €230,933.57 in cryptocurrency proceeds do not establish how many systems were infected.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/malicious-npm-package-indexed-btree-hid.html)

---
Canonical: https://techandbusiness.org/newswire/HbGr9Rdca6bGslxY8c3nk8
Published: 2026-09-22T12:08:31.270Z
Story chronology: 2026-09-22T09:38:18.000Z
Retrieved: 2026-09-22T13:43:23.969Z
Publisher: Tech & Business (techandbusiness.org)
