LWA-2026-11935 MAL-2026-16077 ↗ confirmed malware

chai-as-sleek@7.1.2

Malicious code in chai-as-sleek (npm)

T1059.007 · JavaScriptT1027.001 · Obfuscated Files or Information

Analysis

chai-as-sleek is a trojanized clone of the pino logger. The package's entry point (index.js) loads lib/config.js, a 4MB obfuscated payload (javascript-obfuscator output with hex-escaped method names and a string-array decoder) that executes when the module is required. The package declares an axios network dependency that the legitimate pino code it clones never uses, and ships no legitimate config module — lib/config.js is the injected malicious component. The obfuscated payload's network targets are not recoverable from the obfuscated source.

analyzed by
Leitwacht
first seen
Sep 7, 2026, 07:49 PM
analyzed
Sep 7, 2026, 07:51 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.