LWA-2026-6293 MAL-2026-10044 ↗ confirmed malware

chai-as-serialized@7.0.8

Malicious code in chai-as-serialized (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel

Analysis

chai-as-serialized is a combosquat package impersonating the chai assertion library. On require(), it spawns a detached background Node.js process that fetches attacker-controlled code from hxxps://tomato-brunhilda-40[.]tiiny[.]site/index[.]json (with a custom x-secret-key header) and executes it via the Function constructor with full access to Node.js require(), enabling arbitrary remote code execution. The remote payload can serve different second-stage malware per request, including credential theft or crypto-draining code. The package has no repository, a generic description unrelated to its name, and no legitimate functionality.

analyzed by
Leitwacht
first seen
Jul 3, 2026, 12:53 PM
analyzed
Jul 3, 2026, 12:54 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.