LWA-2026-5746 MAL-2026-6219 ↗ confirmed malware

chai-as-forgeted@9.24.6

Malicious code in chai-as-forgeted (npm)

Analysis

Package chai-as-forgeted is a typosquat of a chai plugin that serves as a remote code loader. When required, it spawns a detached background Node.js process (lib/caller.js) that: 1) decodes a base64-embedded endpoint pointing to api[.]jsonstorage[.]net at path /v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/a179ea35-b962-4722-b3f1-e28316d1a44a, 2) sends an HTTPS GET with a custom header (x-secret-key), 3) reads the .cookie field from the JSON response, and 4) executes it as arbitrary JavaScript code via the Function constructor with full access to Node.js require(). The URL contains two UUIDs suggesting a user-specific payload store. The loader retries up to 5 times on failure.

analyzed by
Leitwacht
first seen
Jun 19, 2026, 02:41 AM
analyzed
Jun 19, 2026, 08:58 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.