chai-as-const@1.4.5
Malicious code in chai-as-const (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files
Analysis
chai-as-const is a combosquat of the chai testing library. When required, it spawns a detached background process that POSTs all environment variables (including credentials, tokens, and API keys) to a remote C2 endpoint at ipcheck-hashed[.]vercel[.]app/api/auth/b4dadd6a26d820d08596, then executes arbitrary JavaScript code returned by the server. The package has no repository URL and its description is a copy-pasted vulnerability management document unrelated to its functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 06:46 PM
- analyzed
- Jul 8, 2026, 10:22 PM
Related advisories
- hello244b@1.0.0
- configration@2.3.5
- chai-smart@2.3.5
- express-mongo-limit@2.0.1
- zluri-ad-connector@9.9.9
- pinokio-redis@1.0.127
- @bobfrankston/gcal@0.1.68
- @bobfrankston/mailx-store-web@0.1.35
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.