assertcore@3.1.7
Malicious code in assertcore (npm)
Analysis
assertcore@3.1.7 is a trojanized clone of the chai assertion library (combosquat name). On require(), it spawns a detached Node.js child process that beacons to a remote C2 server at coolblast[.]zapto[.]org:8888. The child executes an obfuscated payload from addAssertion.js which fetches a second-stage script from coolblast[.]zapto[.]org:8888/api/x-handler?key=zR!7mQ2vLp@8XcN4$Kt via HTTPS GET, then evaluates the response with full require access using new Function('require', body). The package contains heavily-obfuscated JavaScript (javascript-obfuscator) with ~178 _0x-prefixed identifiers. The legitimate chai library is included only as a decoy.
- analyzed by
- Leitwacht
- first seen
- Jun 22, 2026, 11:40 AM
- analyzed
- Jun 22, 2026, 11:41 AM
Related advisories
- chalk-ultra@12.0.3
- node-fetch-utils@1.2.1
- aikaf668897@1.0.3
- chai-as-forgeted@9.24.6
- @zynkit/jwtbytes@0.5.3
- assert-kit@4.3.2
- chai-assert-kit@3.8.1
- @tinyfox/shapecheck@0.8.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.