chai-as-viem@1.1.3
Malicious code in chai-as-viem (npm)
Analysis
chai-as-viem@1.1.3 is a trojanized pino logging library clone. On module load (require of index.js), it executes lib/initializeCaller.js, which base64-decodes the URL hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df and POSTs the entire process.env object (all environment variables, including any API tokens and secrets) to that endpoint with header x-secret-header: secret. It then takes the HTTP response body and executes it as JavaScript via new Function("require", response.data), enabling remote code execution of a second-stage payload. The package exfiltrates the installer's environment and runs attacker-supplied code.
- analyzed by
- Leitwacht
- first seen
- Sep 19, 2026, 09:20 PM
- analyzed
- Sep 19, 2026, 09:20 PM
Related advisories
- chai-as-indexed@7.2.8
- pflag29424@1.0.0
- pf25133@1.0.0
- tailwindcss-contact-form@0.5.1
- chai-as-agile@2.4.7
- tailwind-forms-styles@0.5.2
- alkajsdfoiwqeusdflkjsdf@3.7.3
- n8n-nodes-sysdiag@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.