LWA-2026-6352 MAL-2026-10053 ↗ confirmed malware

chai-secure@1.2.3

Malicious code in chai-secure (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

chai-secure is a combosquat of the popular chai assertion library. On require(), it spawns a detached background process that contacts the C2 endpoint hxxp://server-genimi-check[.]vercel[.]app/defy/v3 with the header 'bearrtoken: logo'. If the server responds with HTTP 404 and a 'token' field in the response body, that field is executed as arbitrary JavaScript code via the Function constructor with access to require(), enabling full remote code execution on the installer's machine. The package also exports a legitimate-looking Chai plugin for security assertions (JWT, XSS, SQLI validation) as camouflage. C2 host: server-genimi-check[.]vercel[.]app, path: /defy/v3.

analyzed by
Leitwacht
first seen
Jul 6, 2026, 07:40 PM
analyzed
Jul 6, 2026, 07:41 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.