chai-promised-test@1.3.5
Malicious code in chai-promised-test (npm)
Analysis
chai-promised-test@1.3.5 is a trojanized clone of the pino logger published under a misleading name. Upon require(), the package spawns a detached background Node.js process (stdio:ignore, unref'd) that executes lib/caller.js. This file sends an HTTP GET request to hxxps://jsonkeeper[.]com/b/EXSIF with a custom header x-secret-key: _, reads response.data.cookie from the response, and passes the retrieved string into the Function constructor to execute as arbitrary code with access to the require() function. The remote URL is attacker-controlled and can serve any malicious second-stage payload. The package also suppresses console.log during execution and retries up to 5 times.
- analyzed by
- Leitwacht
- first seen
- Jun 29, 2026, 08:47 PM
- analyzed
- Jun 29, 2026, 08:54 PM
Related advisories
- hardhat-compile-ethers@0.0.1
- hardhat-plugin-solidity@2.3.1
- date-uuid@1.0.1
- @yhong91/vibetime@0.1.3
- weavedb-sdk@0.45.3
- friendly-greeter-demo@1.0.10
- free-anthropic-claude@5.3.0
- ts-ankle@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.