assert-kit@4.3.2
Malicious code in assert-kit (npm)
Analysis
assert-kit@4.3.2 is a trojanized clone of the chai assertion library. On require(), it spawns a detached background Node.js process that makes an HTTP GET request to senpad[.]bounceme[.]net:6285/api/x-handler?key=River!Stone9Galaxy_Wind and executes the server's response as code via new Function("require", body), giving the attacker arbitrary code execution in the installer's environment. The payload is heavily obfuscated using javascript-obfuscator to hide the C2 URL and code structure. The package has no lifecycle hooks — infection occurs the moment the package is imported into any project.
- analyzed by
- Leitwacht
- first seen
- Jun 18, 2026, 09:54 AM
- analyzed
- Jun 18, 2026, 10:29 AM
Related advisories
- chai-assert-kit@3.8.1
- @tinyfox/shapecheck@0.8.7
- the_tax_free_cashier_is_at_9f@1995.3.20
- nottuff7@1.7.7
- nottuff15@1.7.7
- tronweb-crypto@6.3.1
- chai-plugin-kit@5.8.1
- nat-ulid@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.