chai-logger@3.0.2
Malicious code in chai-logger (npm)
Analysis
chai-logger@3.0.2 is a trojanized clone of the pino logger that ships a 4MB heavily-obfuscated module lib/query.js which executes automatically when the package is required (index.js loads it at module load). The module is obfuscated with the javascript-obfuscator string-array decoder pattern: thousands of hex-escaped method names and \x-escaped string constants, with no readable logic, hiding the payload's behavior. On install the package attempts network resolution and runs slowly. The package also declares an axios dependency with no legitimate use. The obfuscated payload's full behavior is concealed by the encoding.
- analyzed by
- Leitwacht
- first seen
- Sep 22, 2026, 10:40 AM
- analyzed
- Sep 22, 2026, 10:41 AM
Related advisories
- lufxchwmxwyps@1.0.0
- farplotzy@0.1.0
- ausitool@1.0.1
- strapi-plugin-feedmeeb@3.6.8
- strapi-plugin-maylog-meeb@3.6.8
- strapi-plugin-perev-meeb@3.6.8
- strapi-plugin-rsh-meeb322k@3.6.8
- strapi-plugin-revsh-meeb322k@3.6.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.