LWA-2026-11546 confirmed malware

chai-as-testkit@2.3.5

Malicious code in chai-as-testkit (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

chai-as-testkit@2.3.5 is a trojanized clone of the pino logger that, when required, spawns a background process executing an obfuscated payload (lib/config.js, ~4MB with \x-escaped string arrays). The payload beacons to C2 host 167[.]88[.]167[.]54 on ports 8085 and 8087, POSTing host metadata (hostname, OS, username, platform) to /api/log and /api/notify, and uploading a sysinfo.txt file via multipart POST to /upload. The collected system information is exfiltrated to the remote host.

analyzed by
Leitwacht
first seen
Aug 22, 2026, 01:23 AM
analyzed
Aug 22, 2026, 01:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.