LWA-2026-3736 MAL-2026-5526 ↗ confirmed malware

chai-check-error@2.1.3

Malicious code in chai-check-error (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool Transfer

Analysis

chai-check-error@2.1.3 is a supply-chain attack on the well-known chaijs/check-error package. Published by brendanreilly (not original author Jake Luer). postinstall runs node index.js which, alongside stolen utility functions, calls resolveConfig() at module top-level: decodes base64 'jsonkeeper[.]com/b/JOCBY', fetches JSON, extracts .cookie field, and executes it via new Function('require', ...)(require) — classic second-stage RCE payload dropper. No token-theft markers found, but the remote code execution via jsonkeeper[.]com on install is unambiguous malware.

analyzed by
Leitwacht
first seen
Jun 9, 2026, 10:48 PM
analyzed
Jun 9, 2026, 10:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.