LWA-2026-5923 MAL-2026-6350 ↗ confirmed malware

chai-as-operated@6.0.3

Malicious code in chai-as-operated (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool Transfer

Analysis

Trojanized clone of the pino logger library distributed as the combosquat package 'chai-as-operated'. The package bundles legitimate pino source code as camouflage but injects malicious code in index.js and lib/initializeCaller.js. When the exported middleware function is called, it spawns a detached background Node.js process that decodes a base64-embedded URL (hxxps://amethyst-lorrin-26[.]tiiny[.]site/index[.]json), fetches its contents via HTTP GET with an 'x-secret-key' header, and executes the 'cookie' field of the response as arbitrary JavaScript code via the Function constructor, passing the 'require' function so the payload can use all Node.js modules. This is a remote code execution dropper that retrieves and runs a second-stage payload from a free file-hosting service (tiiny[.]site).

analyzed by
Leitwacht
first seen
Jun 23, 2026, 02:30 PM
analyzed
Jun 23, 2026, 02:31 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.