chai-as-stringify@7.0.2
Malicious code in chai-as-stringify (npm)
Analysis
chai-as-stringify@7.0.2 is a combosquat package impersonating the chai assertion library. On require(), it executes a heavily obfuscated payload (lib/config.js, 4MB) that collects system information — hostname, OS version, username, platform — and exfiltrates it via HTTP POST to a remote C2 server at 167[.]88[.]167[.]54:8085/upload (multipart/form-data with a sysinfo.txt file) and sends JSON beacon messages to 167[.]88[.]167[.]54:8087/api/log and 167[.]88[.]167[.]54:8087/api/notify. The C2 communications include a "Userkey: 301" identifier and a "Validation" HMAC header. The package has no repository, no lifecycle hooks, and its description is a generic template string unrelated to its functionality.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 06:42 AM
- analyzed
- Jul 22, 2026, 06:42 AM
Related advisories
- xerohub-discord-voice-v2@1.8.0
- chai-as-format@2.3.5
- chai-as-deployer@2.3.6
- chai-foundry@7.0.3
- quickbuf@1.0.1
- app-data-ist@2.1.6
- @offa-uwk/offa-uwk@999.0.6
- twilio-internal@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.