{"id":"MAL-2026-10044","summary":"Malicious code in chai-as-serialized (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (30e48e8980927471640c6573406d988d1a4361759f14a952da36c5daa1c9fd3c)\nThe package's main entry (index.js) spawns a detached `node` child process running lib/initializeCaller.js as a side effect of invoking the exported middleware factory. lib/initializeCaller.js constructs a fake `process.env` object whose fields hold base64 blobs; DEV_API_KEY decodes to https://tomato-brunhilda-40.tiiny.site/index.json and DEV_SECRET_KEY/DEV_SECRET_VALUE decode to an `x-secret-key` request header. The script fetches the JSON body from that anonymous host and executes it via `new Function.constructor(\"require\", response)(require)`, granting the remote host arbitrary code execution with `require` access in the installer/consumer's Node process. The package name mimics `chai-as-promised` and the README is copied from `pino` (pino badges, pino narrative, keywords `fast,logger,stream,json`), while the shipped code has no relation to either — the impersonation is a lure to attract installs to a remote-code-execution dropper. Base64-encoding of the C2 URL and header, disguised as environment-variable configuration, confirms hostile intent.\n","aliases":["GHSA-9q7j-cc9w-c9rf"],"modified":"2026-09-01T11:31:28.463098911Z","published":"2026-07-09T15:32:33Z","database_specific":{"malicious-packages-origins":[{"versions":["7.0.8"],"id":"IN-MAL-2026-009129","import_time":"2026-07-09T16:20:43.580939347Z","modified_time":"2026-07-09T15:32:33Z","sha256":"30e48e8980927471640c6573406d988d1a4361759f14a952da36c5daa1c9fd3c","source":"amazon-inspector"},{"source":"reversing-labs","versions":["7.0.8"],"id":"RLMA-2026-06126","import_time":"2026-09-01T11:17:28.142794402Z","modified_time":"2026-08-24T16:43:41Z","sha256":"319034be45ea981b6c826e1d94195a614c2d7475f7dd6370d3ea59ba5bc47279"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/chai-as-serialized/v/7.0.8"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9q7j-cc9w-c9rf"}],"affected":[{"package":{"name":"chai-as-serialized","ecosystem":"npm","purl":"pkg:npm/chai-as-serialized"},"versions":["7.0.8"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"lib/initializeCaller.js","sha256":"23436f977c9bbe6d302f0f94e191b3dfd938e5a0417ec098d38b60b0ed0cb14f","tlsh":"9511c08e61fc200c046512e6b62f18126021e8673d86d5e47acc835b1f9567f7d936df"},{"sha256":"9351bfc8ade074f9cf9d571c9f6ca6663f337329e1a12cda461f2bf2065ecd7e","tlsh":"c8019c20ce788e2300ed25824c2a064376719c136928fc1932d7512c0f9d5ff05bf21d","path":"package.json"}],"package_integrity":[{"hashes":{"sha1":"2bf8c3cc40a891bfd04dfa87484e3d767d648cab","sha512_sri":"sha512-wFoyrSTwt7g2A6L2h6F8san7LrYCzsk96kuP8XZEHxnA0j3Aw0WKVPgS7Ny+GlUA3YkXfojOntv3zzgfluLBOg=="},"filename":"chai-as-serialized-7.0.8.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-serialized/MAL-2026-10044.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}