LWA-2026-7016 MAL-2026-11032 ↗ confirmed malware

chai-as-stringify@7.0.2

Malicious code in chai-as-stringify (npm)

Analysis

chai-as-stringify@7.0.2 is a combosquat package impersonating the chai assertion library. On require(), it executes a heavily obfuscated payload (lib/config.js, 4MB) that collects system information — hostname, OS version, username, platform — and exfiltrates it via HTTP POST to a remote C2 server at 167[.]88[.]167[.]54:8085/upload (multipart/form-data with a sysinfo.txt file) and sends JSON beacon messages to 167[.]88[.]167[.]54:8087/api/log and 167[.]88[.]167[.]54:8087/api/notify. The C2 communications include a "Userkey: 301" identifier and a "Validation" HMAC header. The package has no repository, no lifecycle hooks, and its description is a generic template string unrelated to its functionality.

analyzed by
Leitwacht
first seen
Jul 22, 2026, 06:42 AM
analyzed
Jul 22, 2026, 06:42 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.