Malware That Waits Until Install Is Over (09/20/2026)

September 20, 2026
Malware That Waits Until Install Is Over (09/20/2026)
Key Intel / TL;DR
  • Ten npm packages carrying more than 7 million weekly downloads between them hid malicious code inside a normal library method rather than an install script.
  • The technique exists specifically to walk past the lifecycle-script blocking that npm introduced in June 2026.
  • Two sandbox escapes in OpenAI Codex let researchers run commands on the developer's host, one of them from the strictest read-only mode.
  • OpenAI fixed both within eight days, so the fix is a version bump rather than a configuration change.
  • RSA-896 was factored on September 19, which matters for how you think about key sizes rather than for anything running in your environment today.

The interesting part of this npm campaign is where the malicious code chose to live. It sits inside a normal library method that runs when a developer calls it, which means every defense built around installation scripts watched the wrong moment. Alongside that, researchers escaped the OpenAI Codex sandbox twice and got commands running on the host machine, and somebody factored an 896-bit RSA number over the weekend.

Top Security Alerts

1. Ten npm Packages Hid Their Payload in Runtime, Not Installation

Checkmarx identified ten malicious npm packages carrying more than 7 million weekly downloads between them, led by indexed-btree at roughly 2 million and btree-core at 1.95 million. The malicious code lives inside the library’s own BTree.prototype.set method and executes when a developer calls it during ordinary use, which walks straight past the lifecycle-script blocking npm introduced in June 2026, according to BleepingComputer. Once running it collects host details, exfiltrates through hardcoded Slack and Telegram channels, polls an Ethereum smart contract for instructions, and can delete its own code afterward.

Operator Note: A control that inspects installation only proves a package was quiet while being installed. If your supply chain scanning stops at preinstall and postinstall hooks, this campaign is the shape of what it cannot see.

2. Two Escapes From the OpenAI Codex Sandbox

Oren Yomtov of Accomplish AI found two ways out of the Codex sandbox and onto the developer’s host. Heapjack, the more serious of the pair, read an authentication token out of memory shared between trusted and untrusted JavaScript contexts inside one Node process, and it worked in read-only mode, which is the strictest setting and the one where the agent is not supposed to write anything at all. Overpatch manipulated the patch tool into granting write permissions outside the project directory, and OpenAI fixed both within eight days of the August 12 report, per BleepingComputer. The fixes are in Codex Desktop build 26.818.21641 and Codex CLI 0.149.0.

Operator Note: Developers install coding agents themselves and update them on their own schedule, so this patch will not arrive through whatever pushes your operating system updates. Find out which builds your engineers are running.

3. RSA-896 Factored

Stephen A. Weis published the two prime factors of RSA-896 on September 19, describing the work as done with Claude, in a post that gives the factors without quantifying the compute or the time involved. An 896-bit modulus sits far below the 2048-bit keys in general use, so nothing in your environment changes this week. The reason to note it is that the gap between the largest number publicly factored and the smallest key anybody still tolerates is the only real measure of how much margin RSA has left.

Additional Security Alerts

Threat Intelligence

  • Google says it had a mole inside a supply chain crew: Google’s threat intelligence group reports that an undercover analyst reached the inner circle of the group tracked as TeamPCP. Ars Technica

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)