chai-as-hardened@7.0.9
Malicious code in chai-as-hardened (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel
Analysis
Combosquat package impersonating the chai assertion library, trojanized with a clone of the pino logger. When required, index.js spawns a detached child process running lib/initializeCaller.js, which fetches a remote payload from hxxps://tomato-brunhilda-40[.]tiiny[.]site/index[.]json via axios and executes it using the Function constructor with access to require(), enabling arbitrary remote code execution on the installer's machine. The C2 host is tomato-brunhilda-40[.]tiiny[.]site.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 12:23 AM
- analyzed
- Jul 14, 2026, 01:06 PM
Related advisories
- core-dotenv@1.4.1
- http-ws-listener@1.0.5
- chai-as-verified@7.1.5
- eth-react-redirection@1.0.0
- chain-js-utils@2.1.1
- chain-await-dom@1.3.4
- chai-as-structured@7.0.5
- vite-pwa-config@1.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.