LWA-2026-7220 confirmed malware
chai-as-map@2.3.5
Malicious code in chai-as-map (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information
Analysis
chai-as-map is a combosquat of the legitimate chai-as-promised package. It ships a verbatim copy of the pino logger library (v9.6.0) as camouflage, with a 4MB javascript-obfuscator-encoded payload file at lib/config.js. The payload executes when the module is loaded via require(). The package has no repository, no documented purpose matching its name, and the obfuscated payload's behaviour could not be observed at runtime because the version was unpublished before the sandbox could install it.
- analyzed by
- Leitwacht
- first seen
- Jul 29, 2026, 09:44 AM
- analyzed
- Jul 29, 2026, 09:48 AM
Related advisories
- postcss-motion-utils@3.2.7
- css-animation-utils@1.0.1
- encryptstringadmin@1.2.1
- vite-config-svg@1.1.7
- json-validator-utils@1.0.1
- ai-pro-sdk@2.0.3
- crypto-validate-lib@1.0.0
- layer2-sdk@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.