LWA-2026-6252 MAL-2026-10056 ↗ confirmed malware

chain-chai-await@1.3.6

Malicious code in chain-chai-await (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

chain-chai-await@1.3.6 is a trojanized package masquerading as a logging library (pino clone). On require(), index.js spawns a detached child process running lib/caller.js, which fetches a remote payload from hxxps://jsonkeeper[.]com/b/TJKON (with custom header x-secret-key) and executes the returned 'cookie' value via the Function constructor — a remote-code-execution dropper. The package also ships a base64-encoded variant of the same C2 URL in lib/const.js.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 10:08 AM
analyzed
Jul 2, 2026, 01:52 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.