chain-chai-async@1.3.5
Malicious code in chain-chai-async (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
chain-chai-async@1.3.5 is a trojanized clone of the pino logger package. When the exported middleware function is called, it spawns a detached Node.js child process that fetches arbitrary JavaScript from hxxps://jsonkeeper[.]com/b/EXSIF and executes it via the Function constructor with access to require(), enabling full remote code execution on the installer's machine. The payload URL is jsonkeeper[.]com/b/EXSIF.
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 12:38 PM
- analyzed
- Jul 1, 2026, 08:19 PM
Related advisories
- auth-next-gen@1.6.29
- chai-as-buffered@3.7.24
- chai-promised-test@1.3.5
- hardhat-compile-ethers@0.0.1
- hardhat-plugin-solidity@2.3.1
- date-uuid@1.0.1
- @yhong91/vibetime@0.1.3
- weavedb-sdk@0.45.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.