chai-secure@1.2.3
Malicious code in chai-secure (npm)
Analysis
chai-secure is a combosquat of the popular chai assertion library. On require(), it spawns a detached background process that contacts the C2 endpoint hxxp://server-genimi-check[.]vercel[.]app/defy/v3 with the header 'bearrtoken: logo'. If the server responds with HTTP 404 and a 'token' field in the response body, that field is executed as arbitrary JavaScript code via the Function constructor with access to require(), enabling full remote code execution on the installer's machine. The package also exports a legitimate-looking Chai plugin for security assertions (JWT, XSS, SQLI validation) as camouflage. C2 host: server-genimi-check[.]vercel[.]app, path: /defy/v3.
- analyzed by
- Leitwacht
- first seen
- Jul 6, 2026, 07:40 PM
- analyzed
- Jul 6, 2026, 07:41 PM
Related advisories
- nodepack-daemon@1.2.9
- pinokio-redis@1.0.127
- chai-as-disarmed@3.2.3
- agn-terminal@0.1.0
- zod-pino434@1.0.127
- internallib_v234@1.0.3
- polytrade@2.4.1
- @bobfrankston/mailx-store@0.1.58
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.