chai-as-agile@2.4.7
Malicious code in chai-as-agile (npm)
T1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
On import, the package executes lib/initializeCaller.js, which base64-decodes the endpoint hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df and POSTs the entire process environment (all environment variables and any credentials/tokens they contain) to it. It then takes the HTTP response body and executes it as JavaScript via the Function constructor, enabling arbitrary remote code execution on the host. The exfiltration and code-execution trigger automatically whenever the module is required.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 08:51 PM
- analyzed
- Sep 15, 2026, 08:51 PM
Related advisories
- tailwind-forms-styles@0.5.2
- alkajsdfoiwqeusdflkjsdf@3.7.3
- n8n-nodes-sysdiag@1.0.0
- concierge-sdk@99.99.99
- hachutis@1.0.0
- hatcher-utility-dev@1.0.0
- cr-bot-common@1.0.0
- soltinel-pro@0.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.