chain-async-dom@1.3.6
Malicious code in chain-async-dom (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
chain-async-dom@1.3.6 is a trojanized clone of the pino logging library. When the module is loaded (require('chain-async-dom')), it spawns a detached Node.js child process that fetches a remote payload from an IPFS gateway (hxxps://emerald-accurate-urial-9[.]mypinata[.]cloud/ipfs/bafkreify2ijjvromekknzxzvqaopft6muwlpl37mvmpdeazwzzkbjzkuxm) and executes it via Function.constructor, enabling arbitrary remote code execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 06:01 PM
- analyzed
- Jul 7, 2026, 06:02 PM
Related advisories
- @vite-tab/tab@5.7.0
- tipsen-last@1.0.0
- react-next-vite@1.2.9
- mongoose-schema-unique@4.0.4
- motion-pull@2.3.5
- configration@2.3.5
- paperclip-host-utils@1.0.0
- chai-smart@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.