{"id":"MAL-2026-16380","summary":"Malicious code in chai-logger (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (566e54855d730e8555b93da4f8ea81faba72645079a7adcc3a05ea8bf8ad8ee6)\nThe package presents itself as a Chai logging plugin but its main entry `index.js` requires `./lib/query.js`, a ~4 MB obfuscator.io-encoded module (23,868-entry rotated string array, T/j decoder wrappers, hex-property indirection) that executes at the top level as soon as the package is required. The remaining files under `lib/` (proto.js, levels.js, tools.js, etc.) are verbatim copies of pino source, unrelated to the advertised Chai plugin API — a cover story around the obfuscated blob. `package.json` declares `axios ^1.10.0` as a runtime dependency, and the only reference to axios in the shipped code is inside the obfuscated body of `lib/query.js`, giving the payload an HTTP client whose destination is reconstructed at runtime from the rotated string array. Author metadata points to `jsonspack.com`, unrelated to Chai or pino. The combination of import-time execution of a heavily obfuscated payload, a mismatched cover story, copied third-party source used as filler, and an HTTP client declared only for use inside the obfuscated code is the canonical npm credential/data-stealer shape.\n","modified":"2026-09-22T14:30:06.801789425Z","published":"2026-09-22T13:58:43Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020288","import_time":"2026-09-22T14:19:07.85130445Z","modified_time":"2026-09-22T13:58:43Z","sha256":"566e54855d730e8555b93da4f8ea81faba72645079a7adcc3a05ea8bf8ad8ee6","source":"amazon-inspector","versions":["3.0.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/chai-logger/v/3.0.2"}],"affected":[{"package":{"name":"chai-logger","ecosystem":"npm","purl":"pkg:npm/chai-logger"},"versions":["3.0.2"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"df4970a67c9caae5dd2e4603ea726f7624a4c17bb197a1039985a10ff9b56923","tlsh":"f016818d5685d42381cc2793be057ae9b17ae96684cca447ff74bf1c69bc41bc2a0ed0","path":"lib/query.js"},{"sha256":"8a171b5efc6c849d971fd40ffd68d887b371cbe1c27e794044d80316862321b7","tlsh":"23019920debc9e2300ed25525c2a0603ba658c579628fc2932dba12c0fad5ff01ff21d","path":"package.json"}],"package_integrity":[{"filename":"chai-logger-3.0.2.tgz","hashes":{"sha1":"2a2b9aa551c1dc15b11e429c6a3eaf2d78ff392a","sha512_sri":"sha512-uWz/DmRni5nCphVk4CT+Il5BE2u8ekz8SEe54KN/WgJVNlXknS3ILTSWN/zLPs9jUNP3d7bYp5edV7f8p6KKGA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-logger/MAL-2026-16380.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}