chai-as-reformed@1.2.0
Malicious code in chai-as-reformed (npm)
Analysis
chai-as-reformed@1.2.0 is a trojanized logger package that executes remote code on require(). index.js spawns a detached background node process running lib/caller.js, which fetches a payload from hxxps://api[.]jsonstorage[.]net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/f89e8264-86c2-4684-94da-c3f82d59370f (sent with an x-secret-key header) and executes the returned .data.cookie value via the Function constructor with require in scope, giving the remote payload full access to the Node.js runtime. The fetched code is attacker-controlled and can run arbitrary commands, read files, or exfiltrate data on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 05:25 PM
- analyzed
- Aug 10, 2026, 05:26 PM
Related advisories
- dayjs-advanced@1.2.0
- commonjs-assertion@1.2.7
- polymarket-stake-mathss@3.5.2
- runtimekit@1.1.0
- hex-encode-utils@1.0.5
- @noobaihome/amis-uni-area-widget@1.0.0
- neverthrow-js@2.0.0
- postcss-initial-provider@3.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.