chai-as-assured@6.0.4
Malicious code in chai-as-assured (npm)
Analysis
Package "chai-as-assured" is a combosquat of the chai assertion testing library. Its main entry (index.js) exports a middleware function that, when invoked, spawns a stealthy detached Node.js child process that outlives the parent. The child process decodes base64-embedded strings to retrieve a remote URL (hxxps://amethyst-lorrin-26[.]tiiny[.]site/index[.]json) with a custom HTTP header (x-secret-key), fetches content from that URL, and executes the response body as arbitrary JavaScript via the Function constructor with full access to Node.js require. This is a staged remote-code-execution loader where the actual payload is hosted externally on the tiiny[.]site platform and retrieved at runtime. The package's description, keywords, and author metadata are unrelated to its name — it is a trojanized clone with mismatched documentation.
- analyzed by
- Leitwacht
- first seen
- Jun 28, 2026, 05:38 PM
- analyzed
- Jun 28, 2026, 08:36 PM
Related advisories
- chai-as-assured@7.1.2 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.