npm · Malicious package advisory
Malwarechai-as-chain-v2
MAL-2026-2886
Malicious code in chai-as-chain-v2 (npm)
Details
chai-as-chain-v2 is a malicious npm package that when imported downloads a C2 dropper from https://jsonkeeper[.]com/b/FAWPU and executes it (similar to malware in to chai-await-test). --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (d2dd43a8df03dc914cb2bd9c028c452f5fd749767bd2c2faef275a9c840c19c5) The package chai-as-chain-v2 was found to contain malicious code.
Compromised versions (1)
- 1.1.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.