A malicious npm campaign distributing the 'indexed-btree' package and nine related libraries bypasses GitHub's 2026 supply chain defenses by hiding malware in runtime code execution rather than installation scripts. The malware collects system information and uses Ethereum smart contracts for command-and-control, with the campaign achieving millions of downloads across affected packages.