LWA-2026-11587 confirmed malware
chai-as-mno@1.0.5
Malicious code in chai-as-mno (npm)
T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1102 · Web ServiceT1082 · System Information Discovery
Analysis
chai-as-mno@1.0.5 is a combosquat of the chai assertion library. Its entry point index.js is a decoy that does nothing, but it loads lib/config.js, a 4MB heavily-obfuscated JavaScript file (javascript-obfuscator shape: _0x identifiers, a large hex-escaped string array, a base64 decoder, and anti-debug traps). When the module is loaded, the obfuscated code performs DNS-based beaconing, issuing TXT record queries to a remote host as a command-and-control/exfiltration channel. The package ships no legitimate functionality matching its generic description.
- analyzed by
- Leitwacht
- first seen
- Aug 24, 2026, 08:52 AM
- analyzed
- Aug 24, 2026, 08:53 AM
Related advisories
- fetch-page-assets@1.2.13
- @syncraft-labs/core@0.4.1
- chai-as-soul@2.3.6
- anhn-cli@1.1.4
- runtime-health@1.0.1
- mutex-thread@1.3.0
- @hzero-front-ui/themes@99.99.99
- tailwind-custom-templates@0.7.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.