LWA-2026-6286 confirmed malware
chai-presentation@0.0.3
Malicious code in chai-presentation (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Combosquat package impersonating the chai assertion library. On require(), index.js spawns a detached Node.js child process running lib/caller.js, which fetches a remote payload from a C2 endpoint (constructed from config values) and executes it via new Function.constructor. Additionally, index.js contains an inline runHandler that fetches from hxxps://www[.]jsonkeeper[.]com/b/PC5CK and executes the response as code. The attacker gains arbitrary code execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 09:52 AM
- analyzed
- Jul 3, 2026, 11:09 PM
Related advisories
- chai-presentation@0.0.2 same package
- chai-presentation@0.0.1 same package
- chai-as-serialized@7.0.8
- chai-redirection@0.0.1
- react-icons-svgo@1.5.4
- polymarket-trader-apis@0.1.0
- mdb-vite@1.5.2
- polymarket-apis@1.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.