LWA-2026-12319 MAL-2026-16380 ↗ confirmed malware

chai-logger@3.0.2

Malicious code in chai-logger (npm)

T1027 · Obfuscated Files or InformationT1059.007 · JavaScriptT1071 · Application Layer Protocol

Analysis

chai-logger@3.0.2 is a trojanized clone of the pino logger that ships a 4MB heavily-obfuscated module lib/query.js which executes automatically when the package is required (index.js loads it at module load). The module is obfuscated with the javascript-obfuscator string-array decoder pattern: thousands of hex-escaped method names and \x-escaped string constants, with no readable logic, hiding the payload's behavior. On install the package attempts network resolution and runs slowly. The package also declares an axios dependency with no legitimate use. The obfuscated payload's full behavior is concealed by the encoding.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 10:40 AM
analyzed
Sep 22, 2026, 10:41 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.