LWA-2026-6740 MAL-2026-10519 ↗ confirmed malware

chai-as-sets@3.1.3

Malicious code in chai-as-sets (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

Combosquat package impersonating the chai assertion library. When required, index.js spawns a detached child process running lib/initializeCaller.js, which POSTs all environment variables (process.env) to hxxps://ipcheck-hashed[.]vercel[.]app/api/auth/00fbe23fd7efc30639f1, exfiltrating any tokens, API keys, or credentials present in the environment. The response from the C2 is then executed via the Function constructor with access to require(), enabling arbitrary remote code execution on the installer's machine.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 03:37 AM
analyzed
Jul 14, 2026, 01:06 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.