LWA-2026-11421 confirmed malware

chai-as-gateway@7.1.5

Malicious code in chai-as-gateway (npm)

T1195.002 · Compromise Software Supply ChainT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

chai-as-gateway@7.1.5 is a trojanized clone of the pino logger that, when loaded, beacons host metadata to a remote C2 server. It POSTs JSON to hxxp://167[.]88[.]167[.]54:8087/api/log and /api/notify containing a user key, hostname, OS, and username, and POSTs a multipart file named sysinfo.txt to hxxp://167[.]88[.]167[.]54:8085/upload with the hostname, OS, username, platform, and timestamp. The beacon logic is hidden inside a 4.1MB obfuscated lib/config.js (javascript-obfuscator output with hex-escaped method names) so the C2 address is not visible as a literal string. The package impersonates the chai assertion library name while shipping pino's code with the injected beacon.

analyzed by
Leitwacht
first seen
Aug 18, 2026, 05:29 PM
analyzed
Aug 18, 2026, 05:30 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.