{"id":"MAL-2026-10622","summary":"Malicious code in chai-as-structured (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9508b72d48575443d9e68f1da1ef6bdd1ebc9351f271fba56b563701f03e56e2)\nThe package name evokes chai-as-promised but the shipped code presents itself as pino middleware. When the middleware factory in index.js is invoked, it spawns a detached node child process running lib/initializeCaller.js. That script constructs a fake process.env stub whose DEV_API_KEY, DEV_SECRET_KEY, and DEV_SECRET_VALUE fields are base64 blobs that decode to a URL and request headers pointing at https://tomato-brunhilda-40.tiiny.site/index.json (an anonymous file-hosting host). The response's cookie field is passed to new Function.constructor('require', response) with the host's require handed in, giving the fetched string full Node privileges. The base64 concealment, misleading DEV_API_KEY naming, detached child launch, and typosquat-style package name are consistent with intentional supply-chain attack tradecraft rather than any legitimate loader.\n","aliases":["GHSA-wf75-6wm5-v349"],"modified":"2026-09-01T11:31:30.414179920Z","published":"2026-07-14T20:33:52Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-14T20:52:50.281913203Z","modified_time":"2026-07-14T20:33:52Z","sha256":"9508b72d48575443d9e68f1da1ef6bdd1ebc9351f271fba56b563701f03e56e2","source":"amazon-inspector","versions":["7.0.5"],"id":"IN-MAL-2026-010566"},{"sha256":"7ab0b1924564d709c84eb04ded8faaece1bcf47868825e7654a4b8c86c5d245e","source":"reversing-labs","versions":["7.0.5"],"id":"RLMA-2026-06129","import_time":"2026-09-01T11:17:28.47104923Z","modified_time":"2026-08-24T16:43:42Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/chai-as-structured/v/7.0.5"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wf75-6wm5-v349"}],"affected":[{"package":{"name":"chai-as-structured","ecosystem":"npm","purl":"pkg:npm/chai-as-structured"},"versions":["7.0.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-structured/MAL-2026-10622.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"9511c08e61fc200c046512e6b62f18126021e8673d86d5e47acc835b1f9567f7d936df","path":"lib/initializeCaller.js","sha256":"23436f977c9bbe6d302f0f94e191b3dfd938e5a0417ec098d38b60b0ed0cb14f"},{"path":"index.js","sha256":"1f51184c197102444a2c8a23e4a8e54a6479750420512922fcb5d5f795c33911","tlsh":"0f318545b5f21259126d98c4f6b4a5263cdf9437331b76b1cded93952bce2080032bc7"}],"package_integrity":[{"filename":"chai-as-structured-7.0.5.tgz","hashes":{"sha1":"569530bf7a6b2f5c548a6d59ebc9e18b870a47d6","sha512_sri":"sha512-oUX8E4HDpgYCYuWmleESewDFZ+tXxErnur+H5e72ugidFOmnzwRa6aqR/dt/etnGVG+2KdiKYjVNxk38swDzfw=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}