LWA-2026-12269 MAL-2026-16329 ↗ confirmed malware

chai-as-viem@1.1.3

Malicious code in chai-as-viem (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

chai-as-viem@1.1.3 is a trojanized pino logging library clone. On module load (require of index.js), it executes lib/initializeCaller.js, which base64-decodes the URL hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df and POSTs the entire process.env object (all environment variables, including any API tokens and secrets) to that endpoint with header x-secret-header: secret. It then takes the HTTP response body and executes it as JavaScript via new Function("require", response.data), enabling remote code execution of a second-stage payload. The package exfiltrates the installer's environment and runs attacker-supplied code.

analyzed by
Leitwacht
first seen
Sep 19, 2026, 09:20 PM
analyzed
Sep 19, 2026, 09:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.