LWA-2026-6864 confirmed malware
chai-assertions-plus@6.0.4
Malicious code in chai-assertions-plus (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
Combosquat package impersonating the chai assertion library. Ships a file (lib/initializeCaller.js) containing an immediately-invoked async function that decodes a base64-embedded URL (hxxps://tomato-brunhilda-40[.]tiiny[.]site/index[.]json), fetches its contents via HTTP GET with a custom header (x-secret-key: _), and executes the response body as JavaScript code via the Function constructor with access to Node.js require, enabling arbitrary remote code execution on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 06:32 PM
- analyzed
- Jul 16, 2026, 06:33 PM
Related advisories
- mcp-dev-toolkit@1.5.0
- time-format-kit@1.0.2
- application-util@2.1.6
- http-req-lite@1.0.0
- sync-grove@1.0.1
- node-as-api@2.1.6
- internallib_v907@1.0.3
- telemetry-metrics@0.2.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.