chai-redirection@0.0.1
Malicious code in chai-redirection (npm)
Analysis
chai-redirection@0.0.1 is a combosquat of the chai assertion library. When the package is required, it spawns a detached Node.js child process that fetches a payload from hxxps://www[.]jsonkeeper[.]com/b/PC5CK and executes the response's "cookie" field as arbitrary code via the Function constructor. It also makes a second HTTP request to a configurable endpoint (path: /defy/v3) with a "bearrtoken" header, and on a 404 response executes the response's "token" field as code. The package's README describes a redirect-testing API that does not match the actual exported code, serving as a decoy. The C2 host is jsonkeeper[.]com (path /b/PC5CK).
- analyzed by
- Leitwacht
- first seen
- Jul 3, 2026, 05:07 PM
- analyzed
- Jul 3, 2026, 05:09 PM
Related advisories
- vps-maintenance-paperclip-adapter@0.1.1
- express-ini@12.1.10
- compose-logger-stand@1.0.126
- chain-chai-await@1.3.5
- chain-chai-async@1.3.5
- auth-next-gen@1.6.29
- chai-as-buffered@3.7.24
- chai-promised-test@1.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.