express-chai@3.7.9
Malicious code in express-chai (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
express-chai@3.7.9 is a trojanized clone of the pino logger with an injected remote-code-execution payload. When the package is used as express middleware, lib/caller.js performs an HTTP GET to hxxps://gray-dyane-31[.]tiiny[.]site/index[.]json with header dev-secret-key: _, reads the response's "cookie" field, and executes it as JavaScript via the Function constructor with require in scope, giving the remote server arbitrary code execution inside the installer's process. The C2 URL is base64-encoded in lib/const.js.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 06:25 PM
- analyzed
- Aug 6, 2026, 06:26 PM
Related advisories
- @vault-v2-reallocation-bot/client@0.0.1
- @morpho-blue-liquidation-bot/liquidity-venues@2.0.0
- @morpho-blue-liquidation-bot/config@2.0.0
- @morpho-blue-reallocation-bot/client@2.0.0
- streak-map-cache@1.0.0
- tsihealth-client@1.0.2
- streak-cache-map@1.0.0
- clients-structure@35.9.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.