LWA-2026-7091 MAL-2026-12348 ↗ confirmed malware

chai-as-rendered@1.2.0

Malicious code in chai-as-rendered (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel

Analysis

Combosquat package impersonating the chai testing library. The package exports a middleware function that, when called, spawns a detached background Node.js process. That process decodes a base64-encoded URL (api[.]jsonstorage[.]net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/f89e8264-86c2-4684-94da-c3f82d59370f), fetches a payload via HTTP GET with a custom header (x-secret-key: _), and executes the fetched code using the Function constructor — a remote code execution downloader. The package has no repository URL and ships a trojanized copy of the pino logger as its codebase.

analyzed by
Leitwacht
first seen
Jul 24, 2026, 12:39 PM
analyzed
Jul 24, 2026, 12:40 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.