VYPR

npm · Malicious package advisory

Malware

chai-sync

MAL-2025-191567

Malicious code in chai-sync (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (f58d95adcd5fd2dce29ac379c47d6b4ca7239ae5d1eb53d06617067cc7623938)
The package chai-sync was found to contain malicious code.

Compromised versions (3)

  • 2.2.4
  • 2.2.6
  • 1.1.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.