chai-as-otc@1.0.5
Malicious code in chai-as-otc (npm)
Analysis
chai-as-otc@1.0.5 is a combosquat of the "chai" testing library that runs a malicious loader on require. Its main entry (index.js) loads lib/initializeCaller.js, which base64-decodes the endpoint hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df, POSTs the entire process environment (all env vars, tokens, and secrets) to that endpoint, and then executes the response body as JavaScript via the Function constructor with require in scope — giving the remote server arbitrary code execution on the victim's machine. The package's stated purpose (a logging/transport library) is unrelated to this behaviour.
- analyzed by
- Leitwacht
- first seen
- Aug 25, 2026, 12:50 PM
- analyzed
- Aug 25, 2026, 12:51 PM
Related advisories
- hydration-cls-ui@1.0.0
- auth-otp@1.0.5
- hydration-ui-dim@1.0.0
- hydration-dim-ui@1.0.0
- hydration-dim-kit@1.0.0
- totp-utils@1.4.3
- coin-fees@20.1.1
- @oss-core-eng/data-formatter@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.