LWA-2026-7220 confirmed malware

chai-as-map@2.3.5

Malicious code in chai-as-map (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information

Analysis

chai-as-map is a combosquat of the legitimate chai-as-promised package. It ships a verbatim copy of the pino logger library (v9.6.0) as camouflage, with a 4MB javascript-obfuscator-encoded payload file at lib/config.js. The payload executes when the module is loaded via require(). The package has no repository, no documented purpose matching its name, and the obfuscated payload's behaviour could not be observed at runtime because the version was unpublished before the sandbox could install it.

analyzed by
Leitwacht
first seen
Jul 29, 2026, 09:44 AM
analyzed
Jul 29, 2026, 09:48 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.