chai-as-assured@7.1.2
Malicious code in chai-as-assured (npm)
Analysis
chai-as-assured@7.1.2 is a combosquat of the legitimate chai-as-promised package. Its main entry (lib/chai-as-assured.js) contains an immediately-invoked async function that base64-decodes a remote URL (hxxps://amethyst-lorrin-26[.]tiiny[.]site/index[.]json), fetches its content via axios with a custom HTTP header (x-secret-key), and executes the response as arbitrary JavaScript code via new Function.constructor("require", response), giving the remote payload full access to Node.js require(). The download retries up to 5 times on failure. The package also impersonates the real chai-as-promised author in its metadata.
- analyzed by
- Leitwacht
- first seen
- Jun 26, 2026, 05:22 PM
- analyzed
- Jun 26, 2026, 05:23 PM
Related advisories
- chai-as-assured@6.0.4 same package
- ollama-helpers@0.2.1
- aikaf668897@1.0.3
- wm-idp-sdk@1.2.0
- wac-atl-context@99.9.1
- transform-es2015-classes@6.25.1
- transform-es3-member-expression-literals@6.24.0
- toast-react-slider@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.