chai-as-operated@6.0.3
Malicious code in chai-as-operated (npm)
Analysis
Trojanized clone of the pino logger library distributed as the combosquat package 'chai-as-operated'. The package bundles legitimate pino source code as camouflage but injects malicious code in index.js and lib/initializeCaller.js. When the exported middleware function is called, it spawns a detached background Node.js process that decodes a base64-embedded URL (hxxps://amethyst-lorrin-26[.]tiiny[.]site/index[.]json), fetches its contents via HTTP GET with an 'x-secret-key' header, and executes the 'cookie' field of the response as arbitrary JavaScript code via the Function constructor, passing the 'require' function so the payload can use all Node.js modules. This is a remote code execution dropper that retrieves and runs a second-stage payload from a free file-hosting service (tiiny[.]site).
- analyzed by
- Leitwacht
- first seen
- Jun 23, 2026, 02:30 PM
- analyzed
- Jun 23, 2026, 02:31 PM
Related advisories
- pino-zod@1.0.121
- web3-token-helper@1.1.3
- ts-bn-lint-helper@3.1.19
- chai-as-forgeted@9.24.6
- yianzzkf6687@1.0.3
- aikaf6688812@1.0.3
- stitch-design@0.1.0
- panrouter@5.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.