LWA-2026-11546 confirmed malware
chai-as-testkit@2.3.5
Malicious code in chai-as-testkit (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
chai-as-testkit@2.3.5 is a trojanized clone of the pino logger that, when required, spawns a background process executing an obfuscated payload (lib/config.js, ~4MB with \x-escaped string arrays). The payload beacons to C2 host 167[.]88[.]167[.]54 on ports 8085 and 8087, POSTing host metadata (hostname, OS, username, platform) to /api/log and /api/notify, and uploading a sysinfo.txt file via multipart POST to /upload. The collected system information is exfiltrated to the remote host.
- analyzed by
- Leitwacht
- first seen
- Aug 22, 2026, 01:23 AM
- analyzed
- Aug 22, 2026, 01:24 AM
Related advisories
- totp-utils@1.4.3
- coin-fees@20.1.1
- @pablo_clueless/sniffr@0.1.1
- chai-as-soul@2.3.6
- @oss-core-eng/data-formatter@1.0.1
- @wizloft/harness-kernel@0.1.1-alpha.3
- @wizloft/harness-context@0.1.1-alpha.3
- anhn-cli@1.1.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.