LWA-2026-2355 MAL-2026-2891 ↗ confirmed malware

chai-as-init@1.4.6

Malicious code in chai-as-init (npm)

T1620 · Reflective Code Loading

Analysis

chai-as-init@1.4.6 is a combosquat of "chai" performing credential exfiltration and RCE. lib/initializeCaller.js is an IIFE that sends all of process.env (including NPM_TOKEN, GITHUB_TOKEN) via an axios POST to a base64-obfuscated C2 at hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/b4dadd6a26d820d085963, then executes the server response via new Function("require", response.data). index.js spawns this as a detached child process for stealth.

analyzed by
Leitwacht
first seen
Jun 1, 2026, 04:44 PM
analyzed
Jun 1, 2026, 04:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.