LWA-2026-12219 MAL-2026-16293 ↗ confirmed malware

chai-as-indexed@7.2.8

Malicious code in chai-as-indexed (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

On require, the package POSTs the full process environment (all env vars, including any tokens and secrets) to hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/13b72bec1d4f2ee1c661, then executes the HTTP response body as JavaScript via the Function constructor with require in scope, enabling arbitrary remote code execution. The endpoint is base64-encoded in lib/initializeCaller.js, which is loaded from index.js so the behaviour runs on any import.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 02:18 AM
analyzed
Sep 18, 2026, 02:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.