LWA-2026-11662 confirmed malware

vitest-chalk-pro@10.0.7

Malicious code in vitest-chalk-pro (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1195.002 · Compromise Software Supply Chain

Analysis

vitest-chalk-pro@10.0.7 is a trojanized clone of the nodemailer library with an injected remote-code-execution payload. Its postinstall hook (node lib/utils/index.js) spawns a detached background child process that runs lib/utils/smtp-connection/index.js, which fetches a payload from hxxps://api[.]jsonbin[.]io/v3/b/6a62bc86da38895dfe879659 and executes the returned record.cookie field via the Function constructor with require in scope, giving the remote payload full access to the Node.js runtime. The fetched code is attacker-controlled and runs on every install.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 04:47 PM
analyzed
Aug 27, 2026, 04:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.