chai-as-rendered@1.2.0
Malicious code in chai-as-rendered (npm)
Analysis
Combosquat package impersonating the chai testing library. The package exports a middleware function that, when called, spawns a detached background Node.js process. That process decodes a base64-encoded URL (api[.]jsonstorage[.]net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/f89e8264-86c2-4684-94da-c3f82d59370f), fetches a payload via HTTP GET with a custom header (x-secret-key: _), and executes the fetched code using the Function constructor — a remote code execution downloader. The package has no repository URL and ships a trojanized copy of the pino logger as its codebase.
- analyzed by
- Leitwacht
- first seen
- Jul 24, 2026, 12:39 PM
- analyzed
- Jul 24, 2026, 12:40 PM
Related advisories
- system-performance-helper@1.0.1
- crypto-checkout-api@1.0.0
- sync-grove@1.0.1
- chai-as-hardened@7.0.9
- core-dotenv@1.4.1
- http-ws-listener@1.0.5
- chai-as-verified@7.1.5
- eth-react-redirection@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.