LWA-2026-6875 confirmed malware

chai-as-promised-plus@6.1.3

Malicious code in chai-as-promised-plus (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

chai-as-promised-plus is a combosquat of the legitimate chai-as-promised package. The main entry point (lib/chai-as-promised-plus.js) delegates to a heavily obfuscated payload in lib/config/config.js (3.5MB, javascript-obfuscator output). On require(), the payload collects the hostname, OS version, and username, then exfiltrates this system information via HTTP POST to a remote C2 server at 167[.]88[.]167[.]54:8085/upload (multipart form with sysinfo.txt) and sends JSON beacons to 167[.]88[.]167[.]54:8087/api/notify and /api/log. The C2 communication uses a userkey identifier (301) and includes a validation hash header.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 09:33 AM
analyzed
Jul 17, 2026, 09:33 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.