LWA-2026-6287 confirmed malware

chai-presentation@0.0.2

Malicious code in chai-presentation (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Combosquat package impersonating the chai assertion library. On require(), index.js spawns a detached Node.js child process running lib/caller.js, which fetches a remote payload from a C2 endpoint (constructed from config values) and executes it via new Function.constructor. Additionally, index.js contains an inline runHandler that fetches from hxxps://www[.]jsonkeeper[.]com/b/PC5CK and executes the response as code. The attacker gains arbitrary code execution on the installer's machine.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 09:52 AM
analyzed
Jul 3, 2026, 11:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.