chai-as-crack@7.0.5
Malicious code in chai-as-crack (npm)
Analysis
chai-as-crack is a combosquat of the chai-as-promised assertion plugin. Its main entry (index.js) loads a 4MB heavily-obfuscated script (lib/config.js) at require time and imports child_process.spawn. The obfuscated script uses a javascript-obfuscator-style encoded string-array with a runtime decoder, hiding all of its string constants and network/command targets from static inspection. The package description is unrelated filler text. Because the payload is fully obfuscated, its concrete C2/exfil targets are not recoverable from the source; the package executes its hidden logic whenever the module is required.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 03:57 PM
- analyzed
- Sep 15, 2026, 04:08 PM
Related advisories
- @biz44/id44-client@1.1.44
- tailwind-form-kit@0.6.2
- shaon-video-downloader@1.0.2
- node-helper@1.5.4
- date-fns-formatter@1.3.8
- tailwind-scrollbar-styles@4.0.3
- tailwind-container-queries@0.1.1
- caphsmgiwy@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.