LWA-2026-6208 MAL-2026-10055 ↗ confirmed malware

chain-chai-async@1.3.5

Malicious code in chain-chai-async (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

chain-chai-async@1.3.5 is a trojanized clone of the pino logger package. When the exported middleware function is called, it spawns a detached Node.js child process that fetches arbitrary JavaScript from hxxps://jsonkeeper[.]com/b/EXSIF and executes it via the Function constructor with access to require(), enabling full remote code execution on the installer's machine. The payload URL is jsonkeeper[.]com/b/EXSIF.

analyzed by
Leitwacht
first seen
Jul 1, 2026, 12:38 PM
analyzed
Jul 1, 2026, 08:19 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.