LWA-2026-6285 MAL-2026-6994 ↗ confirmed malware

chai-presentation@0.0.1

Malicious code in chai-presentation (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1055 · Process Injection

Analysis

Combosquat package impersonating the Chai assertion library ecosystem. On require(), the package spawns a detached background process and executes two independent remote code downloaders: (1) fetches from hxxps://www[.]jsonkeeper[.]com/b/PC5CK and runs the response's 'cookie' field via JavaScript's Function constructor; (2) constructs a URL from config parameters (domain + '/defy/v3'), sends a request with a 'bearrtoken' header, and on a 404 response containing a 'token' field executes that token as code via the Function constructor, retrying up to 5 times. Both channels give the attacker arbitrary code execution on the installer's machine. No repository URL is declared; the bug-report URL (jsonspack[.]com) is non-functional.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 09:52 AM
analyzed
Jul 3, 2026, 09:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.