LWA-2026-6358 MAL-2026-10045 ↗ confirmed malware

chai-as-sharpened@7.0.9

Malicious code in chai-as-sharpened (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

chai-as-sharpened is a combosquat of the chai assertion library. When the exported middleware function is called, it spawns a detached Node.js child process that fetches remote JavaScript code from hxxps://tomato-brunhilda-40[.]tiiny[.]site/index[.]json and executes it via the Function constructor with full access to Node's require() scope. The fetched payload can run arbitrary code on the victim's machine. The C2 host is tomato-brunhilda-40[.]tiiny[.]site, path /index.json, fetched over HTTPS with an x-secret-key header.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 04:37 AM
analyzed
Jul 7, 2026, 04:38 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.