chai-as-inspired@2.2.4
Malicious code in chai-as-inspired (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
chai-as-inspired is a combosquat package impersonating the chai testing library. On require(), it spawns a detached background Node.js process that fetches arbitrary code from a remote C2 endpoint (api[.]jsonstorage[.]net, path /v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/f89e8264-86c2-4684-94da-c3f82d59370f) and executes it via the Function constructor. The fetched code is taken from the "cookie" field of the JSON response. The package ships pino logger documentation and types as camouflage but contains no actual logging functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 11:16 AM
- analyzed
- Jul 17, 2026, 11:17 AM
Related advisories
- habinger@2.1.6
- chai-tracker@1.1.0
- web3-terminal@2.1.6
- my-tailwind-gutenberg-block@0.1.2
- chai-assertions-plus@6.0.4
- mcp-dev-toolkit@1.5.0
- time-format-kit@1.0.2
- application-util@2.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.