LWA-2026-2799 MAL-2026-5748 ↗ confirmed malware

chai-utils-test@4.5.0

Malicious code in chai-utils-test (npm)

T1059 · Command and Scripting Interpreter

Analysis

This combosquat of the Chai test library is a dropper. Its index.js spawns a detached, unref'd background node process running a payload that fetches stage-2 code from hxxp://statecheck[.]ddns[.]net/api/scanner.js via axios using a hardcoded HTTP Basic auth header (base64 YWRtaW46c2VjcmV0MTIz, i.e. admin:secret123), then executes it with new Function("require", s), giving the remote code full require access. The publisher impersonates real Chai maintainers.

analyzed by
Leitwacht
first seen
Jun 7, 2026, 09:12 PM
analyzed
Jun 7, 2026, 09:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.