chai-plugin-helper@1.7.3
Malicious code in chai-plugin-helper (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer
Analysis
combosquat of the real chai assertion library. On require(), spawns a detached background node process that beacons to senpad[.]bounceme[.]net:6285 via HTTPS GET to /api/x-handler?key=<unique_beacon_token>. The response body is compiled via new Function('require', ...) and immediately executed — a remote code loader that pulls and runs arbitrary second-stage payloads at runtime. The package has no lifecycle hooks; execution triggers on require().
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 10:14 AM
- analyzed
- Jun 16, 2026, 10:15 AM
Related advisories
- xmr-btc-lib-js@1.2.1
- xboxauthwrapper@3.9.8
- work-planner-client@1.0.0
- wordsmith-kit@1.0.0
- check-ulid@3.0.2
- vue-template-compiler-plugin@2.7.16
- vl-ui-contact-card@10.1.1
- @dilxzphrine/libsignal-node@2.5.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.