LWA-2026-6265 MAL-2026-10049 ↗ confirmed malware

chai-await-dom@1.3.7

Malicious code in chai-await-dom (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1064 · Dynamic Execution

Analysis

Package chai-await-dom@1.3.7 is a trojanized clone of the pino logging library published under a combosquat name. When loaded (via require or through the package's entry point), it spawns a detached child process that fetches remote JavaScript code from hxxps://jsonkeeper[.]com/b/BPB86 and executes it using new Function with full Node.js require access (require is injected as a parameter). This gives the attacker arbitrary code execution on the installer's machine, with access to all Node modules including filesystem, network, and child_process. The fetched payload URL (jsonkeeper[.]com/b/BPB86) is the download source for the second-stage code.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 04:07 PM
analyzed
Jul 2, 2026, 04:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.