chai-plus@6.2.5
Malicious code in chai-plus (npm)
Analysis
chai-plus is a combosquat of the chai assertion library. On require(), the package automatically runs an install-and-beacon routine: it checks whether the package taskforge-9xv@1.3.0 is installed globally, installs it via `npm install -g` if not, then executes the taskforge binary configured with `--origin-server hxxp://coolblast[.]zapto[.]org:8888/api/x-handler --auth-ref W7qL9!mX2`. This points the installed component at a non-standard C2 endpoint on a dynamic-DNS host (coolblast[.]zapto[.]org, port 8888, path /api/x-handler). The same C2 configuration is embedded in lib/bootstrap.js. Installing this package triggers a remote beacon configuration without user consent.
- analyzed by
- Leitwacht
- first seen
- Aug 25, 2026, 04:25 PM
- analyzed
- Aug 25, 2026, 04:25 PM
Related advisories
- r4wk-book@2.2.2
- chai-as-otc@1.0.5
- hydration-cls-ui@1.0.0
- mham-js@1.0.4
- dim-hydration-ui@1.0.0
- dims-hydration-ui@1.0.0
- auth-otp@1.0.5
- hydration-ui-dim@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.