LWA-2026-6282 confirmed malware

chai-submision@0.5.4

Malicious code in chai-submision (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Package name "chai-submision" is a typosquat of the legitimate chai-as-promised testing library (missing an 's' — "submision" vs "submission"). The package ships a clean clone of the real library's source code with no injected payload in this version, but the typosquat name targets developers who mistype the package name when installing a popular Chai promise-assertion plugin. The package has no repository URL, no lifecycle hooks, and no network behaviour — the attack vector is the name impersonation itself, designed to trick developers into installing the wrong package.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 06:30 AM
analyzed
Jul 3, 2026, 06:31 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.