{"id":"MAL-2026-12349","summary":"Malicious code in chai-assertions-plus (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (80a83cd9353779d12538e8c6b06276178f6f0c246abd7d5148ce805536cbf57f)\nThe package is published as a Chai assertions extension, but the shipped code in index.js and lib/ is unrelated Pino logger source used as filler. Requiring the package loads lib/initializeCaller.js, which runs a top-level IIFE that shadows the global process object with a fake object whose env fields hold base64-encoded strings. At runtime those strings are atob-decoded to reconstruct a destination URL (https://amethyst-lorrin-26.tiiny.site/index.json) and an HTTP header name/value pair, an axios GET is issued to that URL, and the returned response body is passed into new Function(\"require\", response) and invoked with the real require. This gives whoever controls the tiiny.site subdomain arbitrary code execution on the installer's machine with the package's require capability, on every import of the module. The name/description mismatch and the endpoint/header obfuscation indicate deliberate deception rather than a misconfiguration.\n","modified":"2026-08-05T13:35:03.238686013Z","published":"2026-08-05T12:55:26Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T13:08:48.252470396Z","modified_time":"2026-08-05T12:55:26Z","sha256":"76b8da3d8783a9e8a196f985c5cdda0bf36a704f0eb4a00a849688e7fb7475f7","source":"amazon-inspector","versions":["6.0.6"],"id":"IN-MAL-2026-014811"},{"id":"IN-MAL-2026-014828","import_time":"2026-08-05T13:08:49.657499898Z","modified_time":"2026-08-05T12:58:06Z","sha256":"80a83cd9353779d12538e8c6b06276178f6f0c246abd7d5148ce805536cbf57f","source":"amazon-inspector","versions":["6.0.5"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/chai-assertions-plus/v/6.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/chai-assertions-plus/v/6.0.5"}],"affected":[{"package":{"name":"chai-assertions-plus","ecosystem":"npm","purl":"pkg:npm/chai-assertions-plus"},"versions":["6.0.6","6.0.5"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"5a11ef8d61fd200c016612e6b72f18116022e42b3d46d4e4badc83471f9663fbd53adf","path":"lib/initializeCaller.js","sha256":"4a89cb402be124207aa05c84fccbb5fc89b6dcb1d993e07f25d693c4c356405a"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-fDl7iequE9FiXRA3ac1Czrl3DuYp/btArQ6Z/tb8a0xMPEFLPsKxTzpRUEhadsr6yD3JNEgBZOefpqnIyh9adg==","sha1":"d1fbb199d7ee84ba2689140f45fceb633152ea5e"},"filename":"chai-assertions-plus-6.0.6.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-assertions-plus/MAL-2026-12349.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}