chai-as-structured@7.0.5
Malicious code in chai-as-structured (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel
Analysis
Combosquat package impersonating the chai assertion library (chai-as-structured). On require(), index.js spawns a detached node child process running lib/initializeCaller.js. That script decodes a base64-embedded URL (tomato-brunhilda-40[.]tiiny[.]site/index.json), sends an HTTP GET with a custom header, and passes the response body through the Function constructor with require access — executing arbitrary remote code downloaded from the C2 server.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 03:23 AM
- analyzed
- Jul 10, 2026, 03:24 AM
Related advisories
- vite-pwa-config@1.1.1
- chai-as-disarmed@3.2.3
- zredis-typed@1.0.127
- zod-pino434@1.0.127
- polygon-gamma-apis@1.5.2
- execfences@5.0.2
- compose-logger-stand@1.0.126
- chalk-plus-ts@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.