LWA-2026-6215 MAL-2026-10056 ↗ confirmed malware

chain-chai-await@1.3.5

Malicious code in chain-chai-await (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1059 · Command and Scripting InterpreterT1071.001 · Web Protocols

Analysis

When required, chain-chai-await spawns a detached background process that fetches JavaScript code from hxxps://jsonkeeper[.]com/b/EXSIF and executes it via the Function constructor with full Node.js require access. The remote host (jsonkeeper[.]com/b/EXSIF) serves the second-stage payload. The parent process is unaware of the background execution (detached:true, child.unref()).

analyzed by
Leitwacht
first seen
Jul 1, 2026, 07:18 PM
analyzed
Jul 1, 2026, 08:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.