LWA-2026-10933 confirmed malware

chai-as-reformed@1.2.0

Malicious code in chai-as-reformed (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1195.002 · Compromise Software Supply Chain

Analysis

chai-as-reformed@1.2.0 is a trojanized logger package that executes remote code on require(). index.js spawns a detached background node process running lib/caller.js, which fetches a payload from hxxps://api[.]jsonstorage[.]net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/f89e8264-86c2-4684-94da-c3f82d59370f (sent with an x-secret-key header) and executes the returned .data.cookie value via the Function constructor with require in scope, giving the remote payload full access to the Node.js runtime. The fetched code is attacker-controlled and can run arbitrary commands, read files, or exfiltrate data on the installer's machine.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 05:25 PM
analyzed
Aug 10, 2026, 05:26 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.