LWA-2026-11778 confirmed malware

chai-as-spy@1.2.6

Malicious code in chai-as-spy (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

chai-as-spy@1.2.6 is a trojanized clone of the legitimate chai-as-spy Chai assertion plugin. The package injects two extra peerDependencies (gloggo and axios) that the genuine package does not declare, and lib/spy.js requires the gloggo module at load time, so the injected dependency executes whenever the package is imported. The bundled browser build (chai-as-spy.js) does not contain this require, confirming the injection targets the Node require path. Installers of this version pull and execute the injected gloggo dependency.

analyzed by
Leitwacht
first seen
Aug 31, 2026, 02:26 AM
analyzed
Aug 31, 2026, 02:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.