{"id":"MAL-2026-13446","summary":"Malicious code in express-chai (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (34482e23635422fb5ca5632e68708453f1c99317a31e5e8346c75c4d3466560f)\nexpress-chai presents itself as an Express logger middleware impersonating pino, but its exported middleware factory invokes lib/caller.js which decodes a base64-obfuscated URL (https://gray-dyane-31.tiiny.site/index.json) stored in lib/const.js, fetches a JSON payload via axios with a base64-encoded `dev-secret-key` header, and passes the response's `cookie` field to `new Function.constructor(\"require\", s)`, then invokes the resulting function with the local `require`. This grants the operator of the anonymous tiiny.site host arbitrary code execution inside the installer's Node.js process at middleware setup time, with full access to `require` and the surrounding application context. The destination URL and secret header are base64-encoded rather than plain configuration, and the package's naming, keywords (fast, logger, stream, json), and pino-mirroring script names disguise a remote code loader as a well-known logging library.\n","modified":"2026-08-06T23:50:14.427285498Z","published":"2026-08-06T19:11:04Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-06T23:25:07.094269835Z","modified_time":"2026-08-06T19:11:04Z","sha256":"34482e23635422fb5ca5632e68708453f1c99317a31e5e8346c75c4d3466560f","source":"amazon-inspector","versions":["3.7.9"],"id":"IN-MAL-2026-016744"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/express-chai/v/3.7.9"}],"affected":[{"package":{"name":"express-chai","ecosystem":"npm","purl":"pkg:npm/express-chai"},"versions":["3.7.9"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"7df0784e31fd205c02a222e86b2b95336091f4623406d8c4374cc3535fe5aad5ba3ade","path":"lib/caller.js","sha256":"cb2c1b0cdf9cb22b28726542c4ce033d2ad9197bbc6294bb176051a3e42355c4"},{"sha256":"2d5b58230cd5bf2093cde8b7bf751fee8eee1d76acc4df2a8fb71796cf40dcf3","tlsh":"51d022d310a02440607013b2a61da901f582e8af0c8221183aea64840a366aa3880d6f","path":"lib/const.js"},{"sha256":"96902515c575ebdf7adf510de5ad14e9df32eb6db930949dcf225a67318582be","tlsh":"dc111091b4f5514a064dd4d9b128a526bcf7d83732067db0aaec474927ce10c11b1bd3","path":"index.js"}],"package_integrity":[{"filename":"express-chai-3.7.9.tgz","hashes":{"sha1":"34cc3aeed33a9fbf26e18258d30f649b3922d85e","sha512_sri":"sha512-J3A8e/IC0D3MuksmnYvOKLzYegus2NeQ8/ypH5Oo1IJsQFzE9/AXT0vez7TmsZ0v26NKUH4nnnKirT3yntj+4g=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/express-chai/MAL-2026-13446.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}