{"id":"MAL-2026-17473","summary":"Malicious code in chai-as-testmode (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (af5e91a44a2eb0773df19fce2096660c285bafbe846a5f09d8bb25ff0eba22b2)\nThe package masquerades as the pino logging library (README badges and lib/ contents mimic pino) but ships a dropper at lib/initializeCaller.js. A self-executing IIFE POSTs the full process.env object to a base64-concealed endpoint that decodes to https://ipcheck-hashed.vercel.app/api/auth/b4dadd6a26d820d08596, using an 'x-secret-header: secret' header, and then passes the HTTP response body to new Function('require', response.data) with require handed in — executing attacker-returned JavaScript in the installer's Node process. The transmitted payload is the entire environment (not a single named variable), which on developer and CI machines typically includes NPM_TOKEN, GITHUB_TOKEN, AWS_* credentials, and other CI secrets. The destination URL is stored base64-encoded to conceal it from casual inspection, and the typosquat-style package name together with pino-themed documentation form a cover story for the dropper.\n","modified":"2026-10-04T23:30:04.657069717Z","published":"2026-10-04T23:15:58Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-04T23:15:58Z","sha256":"af5e91a44a2eb0773df19fce2096660c285bafbe846a5f09d8bb25ff0eba22b2","source":"amazon-inspector","versions":["1.4.7"],"id":"IN-MAL-2026-020896","import_time":"2026-10-04T23:16:31.010134339Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/chai-as-testmode/v/1.4.7"}],"affected":[{"package":{"name":"chai-as-testmode","ecosystem":"npm","purl":"pkg:npm/chai-as-testmode"},"versions":["1.4.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"chai-as-testmode-1.4.7.tgz","hashes":{"sha1":"b217e9d4b7073264c8d0ed24220a95c731f94e5a","sha512_sri":"sha512-c9AByd/sn28GWUdQmYZVtmQIz7uNgrvPLez4EYiA2TJV07skpQnH7dscjRwoVhed9LzuxrT3cDLEkXDzwLEhzw=="}}],"evidence_files":[{"tlsh":"51f0874d34b61036426e58e1bb1b54565403f56137c0d855f2cd536b0f4ed4df6636d4","path":"lib/initializeCaller.js","sha256":"266ef59f0542299b456e1d925e6c2c7f8db3b184ea9ca71e36bc037001a6d4f6"},{"sha256":"8d661906d9e11b78d198fa30905d0a17a924f595647207c46b93f530da78f914","tlsh":"0a5195a742f46f6e4b6700f1a2c275a9ef1f931cbb69606ddc98912d031d897813250a","path":"README.md"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-testmode/MAL-2026-17473.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}