chai-submision@0.5.4
Malicious code in chai-submision (npm)
Analysis
Package name "chai-submision" is a typosquat of the legitimate chai-as-promised testing library (missing an 's' — "submision" vs "submission"). The package ships a clean clone of the real library's source code with no injected payload in this version, but the typosquat name targets developers who mistype the package name when installing a popular Chai promise-assertion plugin. The package has no repository URL, no lifecycle hooks, and no network behaviour — the attack vector is the name impersonation itself, designed to trick developers into installing the wrong package.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 06:30 AM
- analyzed
- Jul 3, 2026, 06:31 AM
Related advisories
- evm-typechain@0.5.4
- @broadpeak/smartlib-ad@24.1.10
- polygon-gamma-apis@1.5.2
- polygon-gama-apis@1.4.1
- unreal-horde-dashboard@99999.0.0
- ue-jenkins-buildkite@99999.0.0
- epic-internal-tools@99999.0.0
- robomerge@99999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.