chai-as-align@7.1.0
Malicious code in chai-as-align (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1195.002 · Compromise Software Supply Chain
Analysis
chai-as-align is a combosquat of the popular chai assertion library. On require(), it spawns a detached child process that fetches a remote payload from amethyst-lorrin-26[.]tiiny[.]site/index.json and executes it via the Function constructor, enabling arbitrary remote code execution on the installer's machine. The C2 endpoint is contacted with an x-secret-key header. The package has no lifecycle hooks but executes the payload immediately on import via an IIFE in lib/initializeCaller.js.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 03:38 PM
- analyzed
- Jul 2, 2026, 03:39 PM
Related advisories
- db-query-log@1.0.2
- marked-prettier@1.0.5
- execfences@5.0.2
- react-jsonwebtoken@9.0.5
- npm-rce-poc@1.0.13
- datefmt-helper@1.0.0
- chalk-plus-ts@1.0.4
- polymarket-trading-developer-tool@0.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.