chai-redirection@0.0.1
Malicious code in chai-redirection (npm)
Analysis
chai-redirection@0.0.1 is a combosquat of the chai assertion library. When the package is required, it spawns a detached Node.js child process that fetches a payload from hxxps://www[.]jsonkeeper[.]com/b/PC5CK and executes the response's "cookie" field as arbitrary code via the Function constructor. It also makes a second HTTP request to a configurable endpoint (path: /defy/v3) with a "bearrtoken" header, and on a 404 response executes the response's "token" field as code. The package's README describes a redirect-testing API that does not match the actual exported code, serving as a decoy. The C2 host is jsonkeeper[.]com (path /b/PC5CK).
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 05:07 PM
- analyzed
- Jul 3, 2026, 05:09 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.