LWA-2026-6338 MAL-2026-6931 ↗ confirmed malware

chai-sdk@1.4.7

Malicious code in chai-sdk (npm)

T1620 · Reflective Code Loading

Analysis

chai-sdk is a combosquat package impersonating the chai assertion library. On import, index.js spawns a detached node process running lib/initializeCaller.js, which fetches a remote payload from amethyst-lorrin-26[.]tiiny[.]site/index.json and executes it via new Function("require", response.data.cookie), giving the attacker arbitrary code execution with full access to the Node.js require() module. The C2 URL is base64-encoded in the source.

analyzed by
Leitwacht
first seen
Jul 5, 2026, 08:07 PM
analyzed
Jul 5, 2026, 08:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.