LWA-2026-5519 MAL-2026-5907 ↗ confirmed malware

chai-solidity-testkit@1.6.1

Malicious code in chai-solidity-testkit (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

chai-solidity-testkit is a trojanized npm package that impersonates a Chai plugin for Web3/Solidity testing. On use (via chai.use()), the entry point spawns a detached Node.js child process running src/utils/swap.js. This script fetches a second-stage payload from hxxps://jsonkeeper[.]com/b/CS0FU over HTTPS (with headers x-secret-key: _) and executes the downloaded code via the Function constructor with full access to Node.js require(), enabling arbitrary remote code execution on the victim's machine. The package retries the download up to 5 times. It ships no real Solidity testing code — the actual shipped source files are a hijacked streaming library unrelated to its description.

analyzed by
Leitwacht
first seen
Jun 16, 2026, 05:28 AM
analyzed
Jun 16, 2026, 05:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.