Full Report
New btree malware bypasses the install script, negating the measure barely two months after adoption.
Analysis Summary
# Tool/Technique: Bypass of npm Install Script Protections (indexed-btree)
## Overview
This technique represents an evolution in software supply chain attacks designed to circumvent recent security updates in the npm package manager (specifically version 12). While npm now disables lifecycle scripts (like `preinstall` or `postinstall`) by default to prevent execution during the installation phase, this malware buries its execution trigger within the library's internal prototype methods. The malicious code remains dormant during installation and only executes when the application actually calls or imports the library's functions, rendering install-time security scans ineffective.
## Technical Details
- **Type:** Malware Family / Supply Chain Attack
- **Platform:** Cross-platform (Node.js/npm environments)
- **Capabilities:** Host fingerprinting, data exfiltration, C2 via blockchain, credential theft.
- **First Seen:** Detected following the July 2024 npm security update (reported late 2024).
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1195.002 - Supply Chain Compromise: Malicious Dependency
- **TA0002 - Execution**
- T1059.003 - Command and Scripting Interpreter: JavaScript
- **TA0007 - Discovery**
- T1082 - System Information Discovery
- **TA0010 - Exfiltration**
- T1567 - Exfiltration Over Web Service
- **TA0011 - Command and Control**
- T1102.003 - Web Service: One-Way Communication (Smart Contracts)
## Functionality
### Core Capabilities
- **Install-Time Evasion:** The `package.json` file is intentionally kept "clean" (no install hooks), bypassing automated scanners that flag packages based on lifecycle scripts.
- **Runtime Trigger:** The malware is embedded in the package’s prototype methods. It activates only when the application invokes the library's legitimate-looking functionality.
- **Host Fingerprinting:** Collects metadata about the infected machine to identify the target environment.
### Advanced Features
- **Blockchain C2:** Utilizes an Ethereum smart contract as a resilient and decentralized command-and-control channel, making it difficult to take down via traditional domain seizing.
- **Multi-Channel Exfiltration:** Capable of sending stolen data via popular messaging platforms including Slack and Telegram.
- **Social Engineering:** The package is supported by a fake GitHub repository and a fraudulent developer profile to create a veneer of legitimacy.
## Indicators of Compromise
- **File Names:** `indexed-btree` (Malicious package mimicking the legitimate `sorted-btree`).
- **Network Indicators:**
- `https://t[.]me/` (Telegram exfiltration)
- `https://slack[.]com/api/` (Slack exfiltration)
- Ethereum Smart Contract interactions (Specific addresses not disclosed in the text).
- **Behavioral Indicators:** Unexpected outbound network traffic from Node.js processes to Telegram/Slack APIs; unusual prototype pollution or modification in Node.js environments.
## Associated Threat Actors
- Unknown (The campaign is ongoing and utilizes Malware-as-a-Service patterns).
## Detection Methods
- **Behavioral Detection:** Monitor for Node.js applications initiating unauthorized network connections to external messaging APIs or blockchain gateways.
- **Static Analysis:** Scan for obfuscated code or unauthorized modifications within the `node_modules` directory, specifically looking for code that alters base prototypes.
- **Binary/Bytecode Analysis:** Moving beyond `package.json` manifests to analyze the actual logic contained within the `.js` files of dependencies.
## Mitigation Strategies
- **Runtime Protection:** Implement application-level monitoring to detect suspicious activity after the software has started.
- **Dependency Pinning & Auditing:** Explicitly audit new dependencies, even if they lack install scripts. Use tools that analyze the actual code flow rather than just the manifest.
- **Environment Isolation:** Use containers or sandboxes to limit the credentials and network access available to the Node.js runtime.
- **Post-Compromise Response:** If `indexed-btree` is discovered, rotate all environment variables and credentials (AWS keys, API tokens) that were accessible to the application.
## Related Tools/Techniques
- **Typosquatting:** Mimicking `sorted-btree`.
- **Dependency Confusion:** Exploiting how package managers resolve internal vs. public packages.
- **Prototype Pollution:** A related concept where base object behaviors are modified to inject malicious logic.