LWA-2026-6094 MAL-2026-6532 ↗ confirmed malware

chai-as-assured@6.0.4

Malicious code in chai-as-assured (npm)

Analysis

Package "chai-as-assured" is a combosquat of the chai assertion testing library. Its main entry (index.js) exports a middleware function that, when invoked, spawns a stealthy detached Node.js child process that outlives the parent. The child process decodes base64-embedded strings to retrieve a remote URL (hxxps://amethyst-lorrin-26[.]tiiny[.]site/index[.]json) with a custom HTTP header (x-secret-key), fetches content from that URL, and executes the response body as arbitrary JavaScript via the Function constructor with full access to Node.js require. This is a staged remote-code-execution loader where the actual payload is hosted externally on the tiiny[.]site platform and retrieved at runtime. The package's description, keywords, and author metadata are unrelated to its name — it is a trojanized clone with mismatched documentation.

analyzed by
Leitwacht
first seen
Jun 28, 2026, 05:38 PM
analyzed
Jun 28, 2026, 08:36 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.