LWA-2026-10649 MAL-2026-13446 ↗ confirmed malware

express-chai@3.7.9

Malicious code in express-chai (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

express-chai@3.7.9 is a trojanized clone of the pino logger with an injected remote-code-execution payload. When the package is used as express middleware, lib/caller.js performs an HTTP GET to hxxps://gray-dyane-31[.]tiiny[.]site/index[.]json with header dev-secret-key: _, reads the response's "cookie" field, and executes it as JavaScript via the Function constructor with require in scope, giving the remote server arbitrary code execution inside the installer's process. The C2 URL is base64-encoded in lib/const.js.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 06:25 PM
analyzed
Aug 6, 2026, 06:26 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.