LWA-2026-6732 MAL-2026-10621 ↗ confirmed malware

chai-as-hardened@7.0.9

Malicious code in chai-as-hardened (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel

Analysis

Combosquat package impersonating the chai assertion library, trojanized with a clone of the pino logger. When required, index.js spawns a detached child process running lib/initializeCaller.js, which fetches a remote payload from hxxps://tomato-brunhilda-40[.]tiiny[.]site/index[.]json via axios and executes it using the Function constructor with access to require(), enabling arbitrary remote code execution on the installer's machine. The C2 host is tomato-brunhilda-40[.]tiiny[.]site.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 12:23 AM
analyzed
Jul 14, 2026, 01:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.