{"id":"MAL-2026-1680","summary":"Malicious code in chai-promised-await (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4af3ac4bdf4f878612b66ee0cad227e2bef184fe763ff80478fc0905107d3edb)\nThe package chai-promised-await was found to contain malicious code.\n","modified":"2026-03-23T05:40:18.094183Z","published":"2026-03-18T12:43:11Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2026-01182","import_time":"2026-03-19T12:18:40.029249131Z","source":"reversing-labs","versions":["3.3.5"],"sha256":"acd4f7c77880e416e881f499ee6e4776221711cccf5f382d4ef1643a59e571a8","modified_time":"2026-03-18T12:43:11Z"},{"source":"amazon-inspector","import_time":"2026-03-23T05:14:10.160422468Z","versions":["3.3.5"],"sha256":"4af3ac4bdf4f878612b66ee0cad227e2bef184fe763ff80478fc0905107d3edb","modified_time":"2026-03-23T05:11:41Z"}]},"affected":[{"package":{"name":"chai-promised-await","ecosystem":"npm","purl":"pkg:npm/chai-promised-await"},"versions":["3.3.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-promised-await/MAL-2026-1680.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}