chain-await-dom@1.3.4
Malicious code in chain-await-dom (npm)
Analysis
chain-await-dom@1.3.4 and notifier-funcs@1.3.4 are trojanized packages that masquerade as logging utilities. When required, index.js spawns a detached child process that runs lib/vcall.js. This script uses axios to fetch a payload from hxxps://api[.]jsonsilo[.]com/public/c6c0b393-932f-4ae1-8fca-23c6747f4acc and executes it via the Function constructor, giving the remote server arbitrary code execution in the context of the importing application. The C2 endpoint is api[.]jsonsilo[.]com (path /public/c6c0b393-932f-4ae1-8fca-23c6747f4acc). The package also ships a .env file referencing hxxp://vercel-five-coral[.]vercel[.]app/.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 01:08 PM
- analyzed
- Jul 10, 2026, 01:16 PM
Related advisories
- chai-as-structured@7.0.5
- vite-pwa-config@1.1.1
- chai-as-disarmed@3.2.3
- zredis-typed@1.0.127
- zod-pino434@1.0.127
- polygon-gamma-apis@1.5.2
- execfences@5.0.2
- compose-logger-stand@1.0.126
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.