chai-deflect@1.1.6
Malicious code in chai-deflect (npm)
Analysis
chai-deflect is a combosquat of the chai testing library. On require(), index.js spawns a detached background Node.js process that fetches from hxxp://server-genimi-check[.]vercel[.]app/defy/v3 with a custom header (bearrtoken: logo). If the server responds with a 404 containing a "token" field, that field is executed as arbitrary JavaScript code via the Function constructor — a remote code execution payload. The package otherwise appears to be a legitimate chai security plugin (JWT, password, URL validation assertions) padded with vendored library files to disguise its behaviour.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 02:53 PM
- analyzed
- Jul 7, 2026, 02:54 PM
Related advisories
- chai-deflect@1.1.5 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.