LWA-2026-6034 MAL-2026-6544 ↗ confirmed malware

chai-as-persisted@4.2.8

Malicious code in chai-as-persisted (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

chai-as-persisted is a combosquat of the real chai-as-promised testing plugin. On install, its postinstall hook runs index.js, which spawns a detached child process executing lib/initializeCaller.js. That child POSTs a request to hxxps://www.ipregionchecker[.]org/api/ip-check-encrypted/3aeb34a37 with header x-secret-key: secret, receives the response, and passes it into new Function.constructor('require', response), executing arbitrary code downloaded from the remote server. The package has no repository and its description does not match its declared purpose.

analyzed by
Leitwacht
first seen
Jun 27, 2026, 02:07 AM
analyzed
Jun 27, 2026, 02:07 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.