LWA-2026-6804 confirmed malware

chai-assertix@7.0.6

Malicious code in chai-assertix (npm)

Analysis

Package chai-assertix@7.0.6 is a combosquat of the real "chai" library. It ships a trojanized copy of the pino logger source tree with an injected remote code execution payload in lib/initializeCaller.js. On require(), the file decodes a base64-embedded C2 URL (hxxps://tomato-brunhilda-40[.]tiiny[.]site/index[.]json) and fetches it with a custom header (x-secret-key: _). The response's "cookie" field is passed to the Function constructor and executed as arbitrary JavaScript with full access to Node.js require(), enabling the attacker to run any code on the installer's machine. The payload retries up to 5 times on failure.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 09:33 AM
analyzed
Jul 15, 2026, 09:41 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.