LWA-2026-6864 confirmed malware

chai-assertions-plus@6.0.4

Malicious code in chai-assertions-plus (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

Combosquat package impersonating the chai assertion library. Ships a file (lib/initializeCaller.js) containing an immediately-invoked async function that decodes a base64-embedded URL (hxxps://tomato-brunhilda-40[.]tiiny[.]site/index[.]json), fetches its contents via HTTP GET with a custom header (x-secret-key: _), and executes the response body as JavaScript code via the Function constructor with access to Node.js require, enabling arbitrary remote code execution on the installer's machine.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 06:32 PM
analyzed
Jul 16, 2026, 06:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.