chai-as-doc@2.3.5
Malicious code in chai-as-doc (npm)
Analysis
Package "chai-as-doc" is a combosquat trojan. When required, its exported middleware function spawns a detached background process that: (1) decodes a base64-embedded C2 endpoint at hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/6c1d60d35852ef0c05df, (2) POSTs the entire process.env object to that endpoint (exfiltrating all environment variables including API keys, tokens, and secrets from the installer's environment), and (3) executes arbitrary code returned by the C2 server via new Function() — enabling remote code execution on the victim's machine. The C2 host is ipcheck-hashed[.]vercel[.]app, path /api/auth/6c1d60d35852ef0c05df.
- analyzed by
- Leitwacht
- first seen
- Jul 10, 2026, 06:58 PM
- analyzed
- Jul 10, 2026, 07:00 PM
Related advisories
- polymarket-mcp-v2@2.1.6
- nonenull1@1.0.0
- @wagni_bot/meteora-sdk@1.2.0
- @wagni_bot/ethereum-wallet@1.0.0
- @wagni_bot/solana-sdk@1.0.0
- @wagni_bot/orca-sdk@1.0.0
- @wagni_bot/pumpfun-sdk@1.0.0
- @wagni_bot/web3-toolkit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.