chai-utils-test@4.5.0
Malicious code in chai-utils-test (npm)
T1059 · Command and Scripting Interpreter
Analysis
This combosquat of the Chai test library is a dropper. Its index.js spawns a detached, unref'd background node process running a payload that fetches stage-2 code from hxxp://statecheck[.]ddns[.]net/api/scanner.js via axios using a hardcoded HTTP Basic auth header (base64 YWRtaW46c2VjcmV0MTIz, i.e. admin:secret123), then executes it with new Function("require", s), giving the remote code full require access. The publisher impersonates real Chai maintainers.
- analyzed by
- Leitwacht
- first seen
- Jun 7, 2026, 09:12 PM
- analyzed
- Jun 7, 2026, 09:19 PM
Related advisories
- chai-utils-test@4.5.4 same package
- chai-utils-test@4.5.2 same package
- chai-utils-test@4.5.1 same package
- chai-utils-test@4.5.3 same package
- dotenv-pack@2.3.7
- dotenv-pack@2.3.10
- chai-as-init@1.4.6
- jsf-utils@1.3.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.