chai-as-indexed@6.0.5
Malicious code in chai-as-indexed (npm)
Analysis
chai-as-indexed@6.0.5 is a trojanized clone of the pino logger: it ships pino's source tree and documentation but injects a remote-code loader. The exported middleware in index.js spawns a detached, unref'd background process running `node lib/caller.js`. That script base64-decodes a hardcoded endpoint and header credentials from lib/const.js, issues an HTTPS GET with axios to hxxps://tomato-erminie-2[.]tiiny[.]site/index[.]json, reads the `cookie` field of the JSON response, and executes it with `new Function.constructor("require", response)(require)` — arbitrary remote code execution with full require access, retried up to five times. The remote host is a free static-site service used as a throwaway payload host, so the executed second stage is attacker-controlled and can change at any time. The package name impersonates the chai-as-* family while the code is a copy of pino.
- analyzed by
- Leitwacht
- first seen
- Oct 7, 2026, 02:18 PM
- analyzed
- Oct 8, 2026, 12:01 PM
Related advisories
- chai-as-indexed@7.2.8 same package
- cputil-node@0.6.6
- hardhat-bits@2.21.0
- random-certs@0.0.1
- dotenv-runtime@1.0.0
- @subql/common@5.8.3
- hardhat-spack@3.0.2
- testmgkregme@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.