
Checkmarx did not say what the second-stage loader does, but it did point out that the malware cleans up after itself. It contains “functionality to delete the malware files and remove the trigger code from the main prototype function,” the researchers noted.
Nine more packages broaden the campaign
Checkmarx also identified nine other npm packages linked to the campaign, which were subsequently removed from the registry. These included ordered-kv-index, btree-leaderboard, priority-slot-queue, btree-range-store, btree-core, btree-time-index, btree-lru-cache, neighbor-key-map, and sliding-score-window.
Several of these packages had hundreds of thousands of downloads, while btree-core had more than 1.9 million downloads.
