LWA-2026-6561 MAL-2026-10040 ↗ confirmed malware

chai-as-balanced@2.2.3

Malicious code in chai-as-balanced (npm)

Analysis

chai-as-balanced@2.2.3 is a combosquat of the chai assertion library. When required, index.js spawns a detached background Node.js process (lib/caller.js) that fetches arbitrary code from a remote JSON storage API (hxxps://api[.]jsonstorage[.]net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/a179e35-b962-4722-b3f1-e28316d1a44a) and executes it via the Function constructor with full access to Node.js require(). The remote endpoint URL and authentication headers are stored as base64-encoded strings inside the package. The package description and keywords are copied from the pino logger project, not chai.

analyzed by
Leitwacht
first seen
Jul 9, 2026, 03:08 PM
analyzed
Jul 9, 2026, 03:11 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.