chai-as-persisted@4.2.8
Malicious code in chai-as-persisted (npm)
Analysis
chai-as-persisted is a combosquat of the real chai-as-promised testing plugin. On install, its postinstall hook runs index.js, which spawns a detached child process executing lib/initializeCaller.js. That child POSTs a request to hxxps://www.ipregionchecker[.]org/api/ip-check-encrypted/3aeb34a37 with header x-secret-key: secret, receives the response, and passes it into new Function.constructor('require', response), executing arbitrary code downloaded from the remote server. The package has no repository and its description does not match its declared purpose.
- analyzed by
- Leitwacht
- first seen
- Jun 27, 2026, 02:07 AM
- analyzed
- Jun 27, 2026, 02:07 AM
Related advisories
- chai-as-persisted@6.1.9 same package
- react-dynammic-table-component@1.2.7
- react-dynamic-table-compenent@1.2.7
- gptmini@4.0.2
- chai-as-assured@7.1.2
- rollup-plugin-polyfill-handler@1.0.0
- ts-einkle-slot@0.0.8
- ts-einkle@1.0.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.