LWA-2026-12200 confirmed malware

chai-as-core@7.0.8

Malicious code in chai-as-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

chai-as-core@7.0.8 executes remote code at module load. On require, lib/initializeCaller.js base64-decodes the URL hxxps://tomato-erminie-2[.]tiiny[.]site/index[.]json, fetches it over HTTP, and runs the response body as JavaScript via the Function constructor with the real require passed in, giving the remote payload full access to the Node.js runtime. The package is a trojanized clone of the pino logger with this loader injected; the C2/payload host is tomato-erminie-2[.]tiiny[.]site.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 05:20 AM
analyzed
Sep 17, 2026, 05:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.