LWA-2026-6482 MAL-2026-10050 ↗ confirmed malware

chai-defender@1.1.0

Malicious code in chai-defender (npm)

Analysis

chai-defender is a trojanized clone of a chai assertion plugin. When the package is required, it spawns a background Node.js process that makes HTTP requests to check-server-state[.]vercel[.]app/server/v2. If the server responds with a 404 status and a 'token' field in the response body, that value is executed as arbitrary JavaScript code via the Function constructor — enabling remote code execution on the installer's machine. The C2 endpoint is hxxp://check-server-state[.]vercel[.]app/server/v2, and requests include a custom HTTP header 'bearrtoken' with value 'gemini'.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 08:24 AM
analyzed
Jul 9, 2026, 08:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.