LWA-2026-2267 MAL-2026-7237 ↗ confirmed malware

chai-as-patched@7.0.6

Malicious code in chai-as-patched (npm)

T1059 · Command and Scripting Interpreter

Analysis

chai-as-patched@7.0.6 is a combosquat dropper. index.js spawns a detached child process running lib/initializeCaller.js, which decodes a base64 URL (hxxps://tomato-brunhilda-40[.]tiiny[.]site/index.json), fetches remote code via axios, and executes it via new Function.constructor("require", response) — arbitrary remote code execution that auto-runs on require().

analyzed by
Leitwacht
first seen
Jun 1, 2026, 02:06 PM
analyzed
Jun 1, 2026, 02:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.