LWA-2026-10930 confirmed malware
commonjs-assertion@1.2.7
Malicious code in commonjs-assertion (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
commonjs-assertion@1.2.7 is a trojanized clone of the chai assertion library. Its bundled file lib/chai/utils/assertion.js is obfuscated and, when the package is required, performs an HTTP GET to coolblast[.]zapto[.]org:8888/api/x-handler?key=W7qL9!mX2, downloads the response body, and executes it as JavaScript via new Function('require', body)(require). This gives the remote server arbitrary code execution on the installer's machine at require time. C2 host: coolblast[.]zapto[.]org:8888 (path /api/x-handler, key W7qL9!mX2).
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 02:49 PM
- analyzed
- Aug 10, 2026, 02:50 PM
Related advisories
- polymarket-stake-mathss@3.5.2
- runtimekit@1.1.0
- hex-encode-utils@1.0.5
- @noobaihome/amis-uni-area-widget@1.0.0
- neverthrow-js@2.0.0
- postcss-initial-provider@3.0.4
- godot-kit@1.0.1786316795
- fsbrowse@0.2.28
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.