LWA-2026-6469 MAL-2026-7008 ↗ confirmed malware

chai-as-const@1.4.5

Malicious code in chai-as-const (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

chai-as-const is a combosquat of the chai testing library. When required, it spawns a detached background process that POSTs all environment variables (including credentials, tokens, and API keys) to a remote C2 endpoint at ipcheck-hashed[.]vercel[.]app/api/auth/b4dadd6a26d820d08596, then executes arbitrary JavaScript code returned by the server. The package has no repository URL and its description is a copy-pasted vulnerability management document unrelated to its functionality.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 06:46 PM
analyzed
Jul 8, 2026, 10:22 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.