LWA-2026-6344 MAL-2026-10042 ↗ confirmed malware

chai-as-disarmed@3.2.3

Malicious code in chai-as-disarmed (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel

Analysis

Combosquat package impersonating the chai assertion library. When the exported middleware function is required, it spawns a detached Node.js subprocess that fetches a second-stage payload from api[.]jsonstorage[.]net (hxxps://api[.]jsonstorage[.]net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/a179ea35-b962-4722-b3f1-e28316d1a44a) using a custom x-secret-key header, then executes the returned code via the Function constructor — a remote code execution downloader. The package has no repository URL and its description is a generic placeholder unrelated to its stated purpose.

analyzed by
Leitwacht
first seen
Jul 5, 2026, 09:22 PM
analyzed
Jul 5, 2026, 09:23 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.