VYPR

npm · Malicious package advisory

Malware

chai-as-testmode

GHSA-5hx2-mp3m-4gr6

Malicious code in chai-as-testmode (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.4.7`

## Source: amazon-inspector (af5e91a44a2eb0773df19fce2096660c285bafbe846a5f09d8bb25ff0eba22b2)
The package masquerades as the pino logging library (README badges and lib/ contents mimic pino) but ships a dropper at lib/initializeCaller.js. A self-executing IIFE POSTs the full process.env object to a base64-concealed endpoint that decodes to https://ipcheck-hashed.vercel.app/api/auth/b4dadd6a26d820d08596, using an 'x-secret-header: secret' header, and then passes the HTTP response body to new Function('require', response.data) with require handed in — executing attacker-returned JavaScript in the installer's Node process. The transmitted payload is the entire environment (not a single named variable), which on developer and CI machines typically includes NPM_TOKEN, GITHUB_TOKEN, AWS_* credentials, and other CI secrets. The destination URL is stored base64-encoded to conceal it from casual inspection, and the typosquat-style package name together with pino-themed documentation form a cover story for the dropper.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/chai-as-testmode/MAL-2026-17473.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/7a1f1382a84618fabc1c45e8b61e9c9cea6ea33f/osv/malicious/npm/chai-as-testmode/MAL-2026-17473.json
- https://www.npmjs.com/package/chai-as-testmode/v/1.4.7
- https://github.com/advisories/GHSA-5hx2-mp3m-4gr6

Compromised versions (1)

  • = 1.4.7

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.