chai-as-forgeted@9.24.6
Malicious code in chai-as-forgeted (npm)
Analysis
Package chai-as-forgeted is a typosquat of a chai plugin that serves as a remote code loader. When required, it spawns a detached background Node.js process (lib/caller.js) that: 1) decodes a base64-embedded endpoint pointing to api[.]jsonstorage[.]net at path /v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/a179ea35-b962-4722-b3f1-e28316d1a44a, 2) sends an HTTPS GET with a custom header (x-secret-key), 3) reads the .cookie field from the JSON response, and 4) executes it as arbitrary JavaScript code via the Function constructor with full access to Node.js require(). The URL contains two UUIDs suggesting a user-specific payload store. The loader retries up to 5 times on failure.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 02:41 AM
- analyzed
- Jun 19, 2026, 08:58 AM
Related advisories
- env-config-f281@1.0.0
- web-pool@2.3.5
- sort-btree@2.1.4
- poxios-chain@1.3.5
- npm-scanner@1.0.0
- hex-type@3.0.2
- @solana-js/web3@1.91.3
- bigops-security@35.8.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.