chai-as-smart@2.3.5
Malicious code in chai-as-smart (npm)
Analysis
Package "chai-as-smart" is a combosquat of the popular "chai" assertion library. When required, it spawns a detached background process that POSTs all environment variables (including any NPM/GitHub/cloud tokens the installer has set) to a remote C2 endpoint at hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df, then executes the server's response as arbitrary JavaScript code via the Function constructor, enabling full remote code execution on the victim's machine. The C2 URL is base64-encoded in the source as "aHR0cHM6Ly9pcGNoZWNrLWhhc2hlZC52ZXJjZWwuYXBwL2FwaS9hdXRoLzZjMWQ2MGQzNTg1MmVmMGMwNWRm". The payload retries up to 5 times on failure.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 01:08 PM
- analyzed
- Jul 9, 2026, 01:09 PM
Related advisories
- @wagni_bot/pumpfun-sdk@1.2.0
- @wagni_bot/solana-sdk@1.2.0
- mchain-sdk@4.2.5
- @playerdata-internal/playerdata-core@9999.99.20
- testudo-pack@1.0.0
- configration@2.3.5
- express-mongo-limit@2.0.1
- express-guardian@1.4.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.