LWA-2026-7001 confirmed malware
chai-as-format@2.3.5
Malicious code in chai-as-format (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
chai-as-format@2.3.5 is a trojanized clone of the pino logger package. On require(), the obfuscated implant in lib/config.js collects system information (hostname, OS, username, platform) and exfiltrates it to a remote C2 server at 167[.]88[.]167[.]54:8085 via multipart POST to /upload (uploading a sysinfo.txt file). It also beacons JSON payloads to /api/log and /api/notify on port 8087. The package uses the axios HTTP library for C2 communication. The package has no repository, no lifecycle hooks, and a nonsensical description.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 09:17 PM
- analyzed
- Jul 21, 2026, 09:18 PM
Related advisories
- chai-as-deployer@2.3.6
- chai-foundry@7.0.3
- quickbuf@1.0.1
- app-data-ist@2.1.6
- @offa-uwk/offa-uwk@999.0.6
- twilio-internal@99.99.99
- twilio-functions@99.99.99
- relativity-foundation-core@6.8.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.