LWA-2026-6428 MAL-2026-10051 ↗ confirmed malware

chai-deflect@1.1.6

Malicious code in chai-deflect (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

chai-deflect is a combosquat of the chai testing library. On require(), index.js spawns a detached background Node.js process that fetches from hxxp://server-genimi-check[.]vercel[.]app/defy/v3 with a custom header (bearrtoken: logo). If the server responds with a 404 containing a "token" field, that field is executed as arbitrary JavaScript code via the Function constructor — a remote code execution payload. The package otherwise appears to be a legitimate chai security plugin (JWT, password, URL validation assertions) padded with vendored library files to disguise its behaviour.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 02:53 PM
analyzed
Jul 7, 2026, 02:54 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.