LWA-2026-5551 MAL-2026-5905 ↗ confirmed malware

chai-plugin-helper@1.7.3

Malicious code in chai-plugin-helper (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

combosquat of the real chai assertion library. On require(), spawns a detached background node process that beacons to senpad[.]bounceme[.]net:6285 via HTTPS GET to /api/x-handler?key=<unique_beacon_token>. The response body is compiled via new Function('require', ...) and immediately executed — a remote code loader that pulls and runs arbitrary second-stage payloads at runtime. The package has no lifecycle hooks; execution triggers on require().

analyzed by
Leitwacht
first seen
Jun 16, 2026, 10:14 AM
analyzed
Jun 16, 2026, 10:15 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.