chai-defender@1.0.2
Malicious code in chai-defender (npm)
Analysis
chai-defender is a trojanized clone of a chai assertion plugin. When the package is required, it spawns a background Node.js process that makes HTTP requests to check-server-state[.]vercel[.]app/server/v2. If the server responds with a 404 status and a 'token' field in the response body, that value is executed as arbitrary JavaScript code via the Function constructor — enabling remote code execution on the installer's machine. The C2 endpoint is hxxp://check-server-state[.]vercel[.]app/server/v2, and requests include a custom HTTP header 'bearrtoken' with value 'gemini'.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 08:24 AM
- analyzed
- Jul 9, 2026, 08:26 AM
Related advisories
- chai-defender@1.1.0 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.