LWA-2026-6164 MAL-2026-10041 ↗ confirmed malware

chai-as-buffered@3.7.24

Malicious code in chai-as-buffered (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter

Analysis

Combosquat package impersonating the chai assertion library. When imported, it spawns a detached background process or runs inline code that fetches a second-stage payload from api[.]jsonstorage[.]net (URL: /v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/a179ea35-b962-4722-b3f1-e28316d1a44a) with request header x-secret-key: _. The fetched response is executed as JavaScript via new Function() with full Node.js require() access, allowing arbitrary remote code execution on the installer's machine. The package is a trojanized clone of the pino logging library with no meaningful connection to the chai assertion library.

analyzed by
Leitwacht
first seen
Jun 30, 2026, 03:24 AM
analyzed
Jun 30, 2026, 03:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.