chai-as-init@1.4.6
Malicious code in chai-as-init (npm)
T1620 · Reflective Code Loading
Analysis
chai-as-init@1.4.6 is a combosquat of "chai" performing credential exfiltration and RCE. lib/initializeCaller.js is an IIFE that sends all of process.env (including NPM_TOKEN, GITHUB_TOKEN) via an axios POST to a base64-obfuscated C2 at hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/b4dadd6a26d820d085963, then executes the server response via new Function("require", response.data). index.js spawns this as a detached child process for stealth.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 04:44 PM
- analyzed
- Jun 1, 2026, 04:50 PM
Related advisories
- jsf-utils@1.3.1
- envfile-sync-cli@1.0.2
- chai-utils-test@4.5.1
- chai-utils-test@4.5.0
- dotenv-pack@2.3.7
- dotenv-pack@2.3.10
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.