LWA-2026-6807 MAL-2026-10676 ↗ confirmed malware

commonjs-assert@1.0.3

Malicious code in commonjs-assert (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

Combosquat package impersonating the chai assertion library. On require(), index.js spawns a detached child process running an obfuscated payload in lib/chai/utils/assertion.js. The payload beacons to coolblast[.]zapto[.]org:8888 via HTTP GET to /api/x-handler?key=W7qL9!mX2, then fetches and executes remote code via new Function(). The C2 domain resolved to 10[.]88[.]0[.]1 in sandbox testing.

analyzed by
Leitwacht
first seen
Jul 15, 2026, 10:32 AM
analyzed
Jul 15, 2026, 10:32 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.