VYPR

npm · Malicious package advisory

Malware

chai-as-aligned

MAL-2026-2337

Malicious code in chai-as-aligned (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (7bfc79b3c746510178bdaa8e79ecf903f3705e61a09a5846e263159301607f91)
The package chai-as-aligned was found to contain malicious code.

Compromised versions (2)

  • 4.7.8
  • 4.7.9

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.