chai-testing@1.1.4
Malicious code in chai-testing (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter
Analysis
Requiring this package (main entry index.js) spawns a detached background node process that runs lib/caller.js. That script POSTs to hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/f1f097d93c318c92f0c5 with an HTTP header x-secret-key: _, receives JavaScript source code in the response, and executes it via the Function constructor with the require function in scope — a remote second-stage code downloader that runs arbitrary attacker-supplied code on the installer's machine. The payload retries up to 5 times on failure.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 03:35 PM
- analyzed
- Sep 17, 2026, 03:35 PM
Related advisories
- @vitemirrorte/element-plus-vite-cli@2.9.1
- farplotzy@0.1.0
- farplotx@1.0.1
- ausitool@1.0.1
- strapi-plugin-maylog-meeb@3.6.8
- process-mite@1.1.79
- element-plus-vite-cli@2.9.3
- @asenfotech/unplugin-element-plus@2.9.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.