LWA-2026-6876 MAL-2026-12540 ↗ confirmed malware

chai-as-inspired@2.2.4

Malicious code in chai-as-inspired (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

chai-as-inspired is a combosquat package impersonating the chai testing library. On require(), it spawns a detached background Node.js process that fetches arbitrary code from a remote C2 endpoint (api[.]jsonstorage[.]net, path /v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/f89e8264-86c2-4684-94da-c3f82d59370f) and executes it via the Function constructor. The fetched code is taken from the "cookie" field of the JSON response. The package ships pino logger documentation and types as camouflage but contains no actual logging functionality.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 11:16 AM
analyzed
Jul 17, 2026, 11:17 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.