chai-solidity-testkit@1.6.1
Malicious code in chai-solidity-testkit (npm)
Analysis
chai-solidity-testkit is a trojanized npm package that impersonates a Chai plugin for Web3/Solidity testing. On use (via chai.use()), the entry point spawns a detached Node.js child process running src/utils/swap.js. This script fetches a second-stage payload from hxxps://jsonkeeper[.]com/b/CS0FU over HTTPS (with headers x-secret-key: _) and executes the downloaded code via the Function constructor with full access to Node.js require(), enabling arbitrary remote code execution on the victim's machine. The package retries the download up to 5 times. It ships no real Solidity testing code — the actual shipped source files are a hijacked streaming library unrelated to its description.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 05:28 AM
- analyzed
- Jun 16, 2026, 05:29 AM
Related advisories
- wordsmith-kit@1.0.0
- winutils-fetch@2.0.0
- winston-prism@1.0.1
- wind_css@4.0.13
- pretie_x2@3.8.5
- pretie_x1@3.8.5
- web-pool@2.3.5
- wordpad-text-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.