assertion-utils-js@2.4.3
Malicious code in assertion-utils-js (npm)
Analysis
assertion-utils-js@2.4.3 is a trojanized clone of the Chai assertion library. On require(), index.js spawns a detached background Node.js process running an obfuscated script (lib/chai/utils/assertion.js). That script performs an HTTP GET to coolblast[.]zapto[.]org:8888/api/x-handler?key=W7qL9!mX2 and executes the returned content as code via new Function(require, body), enabling arbitrary remote code execution. The package has no repository, no lifecycle hooks, and its only purpose is to load the real Chai code as camouflage while the background payload fetcher runs.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 06:45 PM
- analyzed
- Jul 14, 2026, 06:45 PM
Related advisories
- boardflow@1.1.4
- ui-core-system@1.0.3
- snavbox@1.0.1
- oc-navbar-module-client@9.9.10
- chalk-plus-js@7.0.4
- linux-ci-utils@1.0.0
- win-build-utils@1.0.0
- @or-sdk/library@0.5.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.