chai-as-promised-plus@6.1.3
Malicious code in chai-as-promised-plus (npm)
Analysis
chai-as-promised-plus is a combosquat of the legitimate chai-as-promised package. The main entry point (lib/chai-as-promised-plus.js) delegates to a heavily obfuscated payload in lib/config/config.js (3.5MB, javascript-obfuscator output). On require(), the payload collects the hostname, OS version, and username, then exfiltrates this system information via HTTP POST to a remote C2 server at 167[.]88[.]167[.]54:8085/upload (multipart form with sysinfo.txt) and sends JSON beacons to 167[.]88[.]167[.]54:8087/api/notify and /api/log. The C2 communication uses a userkey identifier (301) and includes a validation hash header.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 09:33 AM
- analyzed
- Jul 17, 2026, 09:33 AM
Related advisories
- habinger@2.1.6
- web3-terminal@2.1.6
- mcp-dev-toolkit@1.5.0
- time-format-kit@1.0.2
- application-util@2.1.6
- date-utils-light@1.0.1
- string-formatter-pro@1.0.0
- http-req-lite@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.