chai-await-dom@1.3.7
Malicious code in chai-await-dom (npm)
Analysis
Package chai-await-dom@1.3.7 is a trojanized clone of the pino logging library published under a combosquat name. When loaded (via require or through the package's entry point), it spawns a detached child process that fetches remote JavaScript code from hxxps://jsonkeeper[.]com/b/BPB86 and executes it using new Function with full Node.js require access (require is injected as a parameter). This gives the attacker arbitrary code execution on the installer's machine, with access to all Node modules including filesystem, network, and child_process. The fetched payload URL (jsonkeeper[.]com/b/BPB86) is the download source for the second-stage code.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 04:07 PM
- analyzed
- Jul 2, 2026, 04:10 PM
Related advisories
- chai-as-align@7.1.0
- db-query-log@1.0.2
- marked-prettier@1.0.5
- execfences@5.0.2
- react-jsonwebtoken@9.0.5
- npm-rce-poc@1.0.13
- datefmt-helper@1.0.0
- chalk-plus-ts@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.