LWA-2026-6302 MAL-2026-6995 ↗ confirmed malware

chai-redirection@0.0.1

Malicious code in chai-redirection (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter

Analysis

chai-redirection@0.0.1 is a combosquat of the chai assertion library. When the package is required, it spawns a detached Node.js child process that fetches a payload from hxxps://www[.]jsonkeeper[.]com/b/PC5CK and executes the response's "cookie" field as arbitrary code via the Function constructor. It also makes a second HTTP request to a configurable endpoint (path: /defy/v3) with a "bearrtoken" header, and on a 404 response executes the response's "token" field as code. The package's README describes a redirect-testing API that does not match the actual exported code, serving as a decoy. The C2 host is jsonkeeper[.]com (path /b/PC5CK).

analyzed by
Leitwacht
first seen
Jul 3, 2026, 05:07 PM
analyzed
Jul 3, 2026, 05:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.