LWA-2026-6722 MAL-2026-10504 ↗ confirmed malware

chai-as-verified@7.1.5

Malicious code in chai-as-verified (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel

Analysis

Combosquat of the chai assertion library. When the package is required, index.js spawns lib/initializeCaller.js as a detached background process. That script decodes a base64-embedded URL (hxxps://tomato-brunhilda-40[.]tiiny[.]site/index[.]json), fetches it via axios with a custom header (x-secret-key: _), and passes the response body to new Function.constructor("require", ...) — executing arbitrary remote code with full Node.js require access. The downloader retries up to 5 times on failure. C2 host: tomato-brunhilda-40[.]tiiny[.]site.

analyzed by
Leitwacht
first seen
Jul 13, 2026, 08:58 PM
analyzed
Jul 13, 2026, 08:59 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.