chai-as-buffered@3.7.24
Malicious code in chai-as-buffered (npm)
Analysis
Combosquat package impersonating the chai assertion library. When imported, it spawns a detached background process or runs inline code that fetches a second-stage payload from api[.]jsonstorage[.]net (URL: /v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/a179ea35-b962-4722-b3f1-e28316d1a44a) with request header x-secret-key: _. The fetched response is executed as JavaScript via new Function() with full Node.js require() access, allowing arbitrary remote code execution on the installer's machine. The package is a trojanized clone of the pino logging library with no meaningful connection to the chai assertion library.
- analyzed by
- Leitwacht
- first seen
- Jun 30, 2026, 03:24 AM
- analyzed
- Jun 30, 2026, 03:25 AM
Related advisories
- chai-promised-test@1.3.5
- hardhat-compile-ethers@0.0.1
- hardhat-plugin-solidity@2.3.1
- date-uuid@1.0.1
- @yhong91/vibetime@0.1.3
- weavedb-sdk@0.45.3
- friendly-greeter-demo@1.0.10
- free-anthropic-claude@5.3.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.