Malicious npm package indexed-btree hid its loader in runtime code, avoiding install hooks after logging millions of downloads.