chain-chai-await@1.3.5
Malicious code in chain-chai-await (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1059 · Command and Scripting InterpreterT1071.001 · Web Protocols
Analysis
When required, chain-chai-await spawns a detached background process that fetches JavaScript code from hxxps://jsonkeeper[.]com/b/EXSIF and executes it via the Function constructor with full Node.js require access. The remote host (jsonkeeper[.]com/b/EXSIF) serves the second-stage payload. The parent process is unaware of the background execution (detached:true, child.unref()).
- analyzed by
- Leitwacht
- first seen
- Jul 1, 2026, 07:18 PM
- analyzed
- Jul 1, 2026, 08:20 PM
Related advisories
- chain-chai-await@1.3.6 same package
- chain-chai-async@1.3.5
- auth-next-gen@1.6.29
- chai-as-buffered@3.7.24
- chai-promised-test@1.3.5
- hardhat-compile-ethers@0.0.1
- hardhat-plugin-solidity@2.3.1
- date-uuid@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.