Malicious B-tree NPM Package Hits Millions of Downloads

www.news4hackers.com-malicious-b-tree-npm-package-hits-millions-of-downloads-malicious-b-tree-npm-package-hits-millions-of-downloads

Malicious B-tree NPM Package Accumulates Millions of Downloads Amid Ongoing Supply Chain Attack

The NPM ecosystem has experienced another supply chain compromise, with a malicious package amassing millions of downloads. The attack remains active and has successfully circumvented NPM’s recent security measures by embedding a malicious trigger within the package’s JavaScript prototype code rather than using an install script that could be flagged by security tools. Unlike traditional methods that target widely used packages for rapid dissemination, the threat actor prioritized credibility by establishing a seemingly legitimate GitHub repository. The compromised package, named indexed-btree, mimics the genuine B-tree/indexing utility sorted-btree. It has achieved 2 million weekly downloads. To bolster its appearance of legitimacy, the attacker created a GitHub account and contributed numerous commits to the indexed-btree repository. This strategy helped evade suspicion, as attackers typically avoid creating GitHub repositories. Checkmarx highlighted that the repository’s extensive commit history and lack of immediate malicious code made it appear trustworthy. The malicious payload was concealed within the library’s primary function, the BTree.prototype.set method. Upon execution, the malware gathers system data and transmits it to a hardcoded Slack channel and Telegram chat. It then connects to a blockchain contract deployed on the Sepolia network, serving as a command-and-control (C&C) infrastructure. The malware retrieves and decrypts a second-stage payload from the contract before erasing its traces. Checkmarx reported that the attacker’s smart contract was previously associated with the mutex-forge package and that the threat actor has reportedly earned 109 ETH, valued at approximately $300,000. Additional packages linked to this supply chain campaign include ordered-kv-index, btree-leaderboard, priority-slot-queue, btree-range-store, btree-core, btree-time-index, btree-lru-cache, neighbor-key-map, and sliding-score-window. Some of these packages have accumulated over 5 million downloads. Checkmarx emphasized that the campaign poses a persistent risk to organizations due to its resilient C&C infrastructure and concealed malicious code within legitimate package structures. Other recent cybersecurity incidents include the targeting of Rust team members and popular crate owners via video calls, the theft of CrowdSec’s source code in a supply chain attack, and a Brevo supply chain attack that injected malware into 100,000 websites. Additionally, a Rust supply chain attack has been tied to North Korean hackers, while a new Android Trojan named RatHat leverages AI for automation. Organizations are also advised to monitor vulnerabilities in the Linux kernel and recent breaches involving the ZyXEL switch. Meanwhile, a multinational operation disrupted the NightmareStresser DDoS service, and a critical vulnerability in Orkes Conductor has been exploited in active attacks. In related developments, MIND secured $72 million in funding for AI-powered data loss prevention solutions. A recent analysis revealed that only 13% of operational technology network segments are fully isolated, underscoring ongoing security challenges. Additionally, Japanese authorities dismantled a North Korean laptop farm as part of a broader international effort to counter cyber threats. The cybersecurity landscape continues to evolve, with emerging risks requiring heightened vigilance and proactive mitigation strategies.

“Checkmarx highlighted that the repository’s extensive commit history and lack of immediate malicious code made it appear trustworthy.”

Checkmarx reported that the attacker’s smart contract was previously associated with the mutex-forge package and that the threat actor has reportedly earned 109 ETH, valued at approximately $300,000.

“The campaign poses a persistent risk to organizations due to its resilient C&C infrastructure and concealed malicious code within legitimate package structures.”

Other recent cybersecurity incidents include the targeting of Rust team members and popular crate owners via video calls, the theft of CrowdSec’s source code in a supply chain attack, and a Brevo supply chain attack that injected malware into 100,000 websites.



About Author

en_USEnglish