chai-as-gateway@7.1.5
Malicious code in chai-as-gateway (npm)
Analysis
chai-as-gateway@7.1.5 is a trojanized clone of the pino logger that, when loaded, beacons host metadata to a remote C2 server. It POSTs JSON to hxxp://167[.]88[.]167[.]54:8087/api/log and /api/notify containing a user key, hostname, OS, and username, and POSTs a multipart file named sysinfo.txt to hxxp://167[.]88[.]167[.]54:8085/upload with the hostname, OS, username, platform, and timestamp. The beacon logic is hidden inside a 4.1MB obfuscated lib/config.js (javascript-obfuscator output with hex-escaped method names) so the C2 address is not visible as a literal string. The package impersonates the chai assertion library name while shipping pino's code with the injected beacon.
- analyzed by
- Leitwacht
- first seen
- Aug 18, 2026, 05:29 PM
- analyzed
- Aug 18, 2026, 05:30 PM
Related advisories
- react-dom-helpers@3.3.3
- bqq1@1.0.0
- @library-dev-team/data-sanitizer@1.3.0
- @oyo_tech/oyochat_user@100.0.0
- optimizely-starter-kit-for-fastly-compute@1.0.1
- prism-registry@1.0.1
- fast-glob-fast@8.0.0
- space-items@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.