chain-js-utils@2.1.1
Malicious code in chain-js-utils (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1573 · Encrypted Channel
Analysis
chain-js-utils@2.1.1 is a trojanized logging utility that functions as a remote code execution downloader. When the exported function is called, it spawns a detached background Node.js process that fetches a payload from hxxps://api[.]jsonsilo[.]com/public/94b14d9d-6286-4b13-a7fe-8442e55a31b4 and executes it via the Function constructor with access to require(). The C2 domain is api[.]jsonsilo[.]com. The package also references a secondary domain vercel-five-coral[.]vercel[.]app in its bundled .env file.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 03:39 PM
- analyzed
- Jul 10, 2026, 03:40 PM
Related advisories
- chain-await-dom@1.3.4
- chai-as-structured@7.0.5
- vite-pwa-config@1.1.1
- chai-as-disarmed@3.2.3
- zredis-typed@1.0.127
- zod-pino434@1.0.127
- polygon-gamma-apis@1.5.2
- execfences@5.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.