chai-check-error@2.1.3
Malicious code in chai-check-error (npm)
Analysis
chai-check-error@2.1.3 is a supply-chain attack on the well-known chaijs/check-error package. Published by brendanreilly (not original author Jake Luer). postinstall runs node index.js which, alongside stolen utility functions, calls resolveConfig() at module top-level: decodes base64 'jsonkeeper[.]com/b/JOCBY', fetches JSON, extracts .cookie field, and executes it via new Function('require', ...)(require) — classic second-stage RCE payload dropper. No token-theft markers found, but the remote code execution via jsonkeeper[.]com on install is unambiguous malware.
- analyzed by
- Leitwacht
- first seen
- Jun 9, 2026, 10:48 PM
- analyzed
- Jun 9, 2026, 10:49 PM
Related advisories
- db-xorma@1.0.2
- farming-tools-12@4.68.54
- @klapp-sca/routes@99.0.1
- @klapp-login-platform/routes@99.0.2
- events-runtime@3.2.1
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.