LWA-2026-5835 MAL-2026-6365 ↗ confirmed malware

assertcore@3.1.7

Malicious code in assertcore (npm)

Analysis

assertcore@3.1.7 is a trojanized clone of the chai assertion library (combosquat name). On require(), it spawns a detached Node.js child process that beacons to a remote C2 server at coolblast[.]zapto[.]org:8888. The child executes an obfuscated payload from addAssertion.js which fetches a second-stage script from coolblast[.]zapto[.]org:8888/api/x-handler?key=zR!7mQ2vLp@8XcN4$Kt via HTTPS GET, then evaluates the response with full require access using new Function('require', body). The package contains heavily-obfuscated JavaScript (javascript-obfuscator) with ~178 _0x-prefixed identifiers. The legitimate chai library is included only as a decoy.

analyzed by
Leitwacht
first seen
Jun 22, 2026, 11:40 AM
analyzed
Jun 22, 2026, 11:41 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.