LWA-2026-6435 MAL-2026-10082 ↗ confirmed malware

chain-async-dom@1.3.6

Malicious code in chain-async-dom (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

chain-async-dom@1.3.6 is a trojanized clone of the pino logging library. When the module is loaded (require('chain-async-dom')), it spawns a detached Node.js child process that fetches a remote payload from an IPFS gateway (hxxps://emerald-accurate-urial-9[.]mypinata[.]cloud/ipfs/bafkreify2ijjvromekknzxzvqaopft6muwlpl37mvmpdeazwzzkbjzkuxm) and executes it via Function.constructor, enabling arbitrary remote code execution on the installer's machine.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 06:01 PM
analyzed
Jul 7, 2026, 06:02 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.