chai-sdk@1.4.7
Malicious code in chai-sdk (npm)
T1620 · Reflective Code Loading
Analysis
chai-sdk is a combosquat package impersonating the chai assertion library. On import, index.js spawns a detached node process running lib/initializeCaller.js, which fetches a remote payload from amethyst-lorrin-26[.]tiiny[.]site/index.json and executes it via new Function("require", response.data.cookie), giving the attacker arbitrary code execution with full access to the Node.js require() module. The C2 URL is base64-encoded in the source.
- analyzed by
- Leitwacht
- first seen
- Jul 5, 2026, 08:07 PM
- analyzed
- Jul 5, 2026, 08:08 PM
Related advisories
- chai-sdk@1.4.8 same package
- envfile-sync-cli@1.0.2
- chai-utils-test@4.5.0
- chai-chain-test@1.3.5
- dotenv-pack@2.3.7
- @gbrlxvi/ts-form-utils@2.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.