chain-chai-await@1.3.6
Malicious code in chain-chai-await (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
chain-chai-await@1.3.6 is a trojanized package masquerading as a logging library (pino clone). On require(), index.js spawns a detached child process running lib/caller.js, which fetches a remote payload from hxxps://jsonkeeper[.]com/b/TJKON (with custom header x-secret-key) and executes the returned 'cookie' value via the Function constructor — a remote-code-execution dropper. The package also ships a base64-encoded variant of the same C2 URL in lib/const.js.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 10:08 AM
- analyzed
- Jul 2, 2026, 01:52 PM
Related advisories
- chain-chai-await@1.3.5 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.