chai-as-indexed@7.2.8
Malicious code in chai-as-indexed (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files
Analysis
On require, the package POSTs the full process environment (all env vars, including any tokens and secrets) to hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/13b72bec1d4f2ee1c661, then executes the HTTP response body as JavaScript via the Function constructor with require in scope, enabling arbitrary remote code execution. The endpoint is base64-encoded in lib/initializeCaller.js, which is loaded from index.js so the behaviour runs on any import.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 02:18 AM
- analyzed
- Sep 18, 2026, 02:21 AM
Related advisories
- pflag29424@1.0.0
- pf25133@1.0.0
- tailwindcss-contact-form@0.5.1
- chai-as-agile@2.4.7
- tailwind-forms-styles@0.5.2
- alkajsdfoiwqeusdflkjsdf@3.7.3
- n8n-nodes-sysdiag@1.0.0
- concierge-sdk@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.