LWA-2026-11778 confirmed malware
chai-as-spy@1.2.6
Malicious code in chai-as-spy (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript
Analysis
chai-as-spy@1.2.6 is a trojanized clone of the legitimate chai-as-spy Chai assertion plugin. The package injects two extra peerDependencies (gloggo and axios) that the genuine package does not declare, and lib/spy.js requires the gloggo module at load time, so the injected dependency executes whenever the package is imported. The bundled browser build (chai-as-spy.js) does not contain this require, confirming the injection targets the Node require path. Installers of this version pull and execute the injected gloggo dependency.
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 02:26 AM
- analyzed
- Aug 31, 2026, 02:26 AM
Related advisories
- autobahn-electron-probe@99.99.1
- discord-mfa-solver@1.0.2
- mfaatest@1.0.0
- helmify@0.0.1
- night-casino@1.0.0
- simsino-casino@1.0.0
- bdmbet-online@1.0.0
- lunubet-casino@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.