chai-as-disarmed@3.2.3
Malicious code in chai-as-disarmed (npm)
Analysis
Combosquat package impersonating the chai assertion library. When the exported middleware function is required, it spawns a detached Node.js subprocess that fetches a second-stage payload from api[.]jsonstorage[.]net (hxxps://api[.]jsonstorage[.]net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/a179ea35-b962-4722-b3f1-e28316d1a44a) using a custom x-secret-key header, then executes the returned code via the Function constructor — a remote code execution downloader. The package has no repository URL and its description is a generic placeholder unrelated to its stated purpose.
- analyzed by
- Leitwacht
- first seen
- Jul 5, 2026, 09:22 PM
- analyzed
- Jul 5, 2026, 09:23 PM
Related advisories
- zredis-typed@1.0.127
- zod-pino434@1.0.127
- polygon-gamma-apis@1.5.2
- execfences@5.0.2
- compose-logger-stand@1.0.126
- chalk-plus-ts@1.0.4
- assertcoreutils@2.3.2
- pino-zod@1.0.121
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.