{"id":"MAL-2026-13692","summary":"Malicious code in chai-jsonss (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3b1fff32102bc74783cae571646ec0fd68b14c614b35a63badd814a64caa3b67)\nOn import, index.js invokes postCallers() which resolves a base64-encoded URL stored in lib/const.js (decoding to https://1uznbx.s.gy/7xdQmt), GETs the response via axios, base64-decodes response.data.model, and passes it to new Function(require) — executing attacker-controlled JavaScript in-process. The destination is hidden as a DEV_API_KEY field on a fake process.env-shaped local module, and the payload URL is a shortlink to a mutable remote resource. The package name resembles chai but its main entry contains no chai-related functionality; the only import-time behavior is fetch-and-eval of remote code.\n","modified":"2026-08-10T12:50:26.528501780Z","published":"2026-08-10T11:56:07Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-10T12:24:46.199172734Z","modified_time":"2026-08-10T11:56:07Z","sha256":"3b1fff32102bc74783cae571646ec0fd68b14c614b35a63badd814a64caa3b67","source":"amazon-inspector","versions":["3.7.7"],"id":"IN-MAL-2026-017246"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/chai-jsonss/v/3.7.7"}],"affected":[{"package":{"name":"chai-jsonss","ecosystem":"npm","purl":"pkg:npm/chai-jsonss"},"versions":["3.7.7"],"database_specific":{"indicators":{"package_integrity":[{"filename":"chai-jsonss-3.7.7.tgz","hashes":{"sha1":"bf71a5b5274da00ab65c28e360f3c4420a4e0482","sha512_sri":"sha512-DAnOczn/xIDDL5bqA4yFYpE9hx/QWxsoy+/ukXmRpl9Hbpvo7bnVo+t5zIKnn+H2mseBbmVkLWHk/5JjY5aKTQ=="}}],"evidence_files":[{"sha256":"2db9b5dcbfbcf4fdf6c46042e0d5ea14324f29e0081fa8edd31d48c889e5baa2","tlsh":"bbe0205f25f8205c157311ccb51688076187d0327141c0f275ec51961fc0f692291bd1","path":"lib/caller.js"},{"tlsh":"49c08cc35094ac965071a233b24daa21f187d34f0c8100013ef0b8840a3a7ba3c84eab","path":"lib/const.js","sha256":"f5940f8a2526599a6132503df100f8d3073b91b8aed775402a8542387c1d8089"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-jsonss/MAL-2026-13692.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}