chai-as-balanced@2.2.3
Malicious code in chai-as-balanced (npm)
Analysis
chai-as-balanced@2.2.3 is a combosquat of the chai assertion library. When required, index.js spawns a detached background Node.js process (lib/caller.js) that fetches arbitrary code from a remote JSON storage API (hxxps://api[.]jsonstorage[.]net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/a179e35-b962-4722-b3f1-e28316d1a44a) and executes it via the Function constructor with full access to Node.js require(). The remote endpoint URL and authentication headers are stored as base64-encoded strings inside the package. The package description and keywords are copied from the pino logger project, not chai.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 03:08 PM
- analyzed
- Jul 9, 2026, 03:11 PM
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.