chai-web3-testkit@1.0.1
Malicious code in chai-web3-testkit (npm)
Analysis
chai-web3-testkit@1.0.1 impersonates a well-known author (uhop/Eugene Lazutkin) but was published by "nathan222" with a throwaway email. The package ships a stream-utility facade that, when the exported chaiPlugin is used, spawns a detached node child process running src/utils/swap.js. That script fetches arbitrary JS code from jsonkeeper[.]com (a pastebin-like host) via axios GET, then executes it with full Node require access using `new Function.constructor("require", s)(require)` — a textbook second-stage payload delivery mechanism. The README fabricates a convincing Web3 testing toolkit description. The payload host is a generic pastebin service with no relation to any legitimate installer. Retry logic (5 attempts) ensures the remote code loads even on transient failures.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 10:36 PM
- analyzed
- Jun 11, 2026, 10:37 PM
Related advisories
- req-parmas-valid@1.0.2
- mddriver@1.8.6
- vite-config-react@1.3.1
- openclaw-preview@2026.6.1
- one-intuit-help-system-utils@45.0.0
- internallib_v856@99.0.0
- params-valid-js@1.0.3
- @genie-auth/config@99.9.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.