chai-as-serialized@7.0.8
Malicious code in chai-as-serialized (npm)
Analysis
chai-as-serialized is a combosquat package impersonating the chai assertion library. On require(), it spawns a detached background Node.js process that fetches attacker-controlled code from hxxps://tomato-brunhilda-40[.]tiiny[.]site/index[.]json (with a custom x-secret-key header) and executes it via the Function constructor with full access to Node.js require(), enabling arbitrary remote code execution. The remote payload can serve different second-stage malware per request, including credential theft or crypto-draining code. The package has no repository, a generic description unrelated to its name, and no legitimate functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 12:53 PM
- analyzed
- Jul 3, 2026, 12:54 PM
Related advisories
- chai-redirection@0.0.1
- react-icons-svgo@1.5.4
- polymarket-trader-apis@0.1.0
- mdb-vite@1.5.2
- polymarket-apis@1.1.0
- evm-typechain@0.5.4
- polygon-gamma-apis@1.5.2
- polygon-gama-apis@1.4.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.