LWA-2026-6607 MAL-2026-10175 ↗ confirmed malware

chai-as-doc@2.3.5

Malicious code in chai-as-doc (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1552.001 · Credentials In Files

Analysis

Package "chai-as-doc" is a combosquat trojan. When required, its exported middleware function spawns a detached background process that: (1) decodes a base64-embedded C2 endpoint at hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df, (2) POSTs the entire process.env object to that endpoint (exfiltrating all environment variables including API keys, tokens, and secrets from the installer's environment), and (3) executes arbitrary code returned by the C2 server via new Function() — enabling remote code execution on the victim's machine. The C2 host is ipcheck-hashed[.]vercel[.]app, path /api/auth/6c1d60d35852ef0c05df.

analyzed by
Leitwacht
first seen
Jul 10, 2026, 06:58 PM
analyzed
Jul 10, 2026, 07:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.