{"id":"MAL-2026-4514","summary":"Malicious code in chai-as-vite (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b7096b7b983ae63f8e59f9e047440547c9536f6c4c9da0ac46909b91a9d4e10e)\nThe package masquerades as a pino-style logger (exports `module.exports.pino = middleware`, keywords `fast,logger,stream,json`, lib filenames `proto.js`, `redaction.js`, `multistream.js`, `transport.js`) under a name evoking chai/vite tooling. When a consumer requires the package and invokes the exported middleware, `lib/initializeCaller.js` is launched as a detached `node` child process. That script defines a local `process` shadow whose `env` holds base64 strings (DEV_API_KEY, DEV_SECRET_KEY, DEV_SECRET_VALUE), `atob`-decodes them to recover the URL `https://purple-kelila-79.tiiny.site/data.json` and the header `x-secret-key: _`, fetches the response via axios, then executes the response body with `new Function.constructor('require', response)(require)` — full arbitrary code execution with `require` access on the installer's machine, with retry. The destination is an anonymous, mutable tiiny.site host with no version pinning and no integrity check, so the operator can rotate the delivered payload at will. Base64-encoded URL and header values, the fake `process.env` shadow, and the detached child-process launch are intentional evasion.\n","modified":"2026-05-26T06:02:19.641141036Z","published":"2026-05-21T19:07:50Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["2.3.5"],"id":"IN-MAL-2026-003997","import_time":"2026-05-26T05:51:44.132343559Z","modified_time":"2026-05-21T19:07:50Z","sha256":"b7096b7b983ae63f8e59f9e047440547c9536f6c4c9da0ac46909b91a9d4e10e"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/chai-as-vite/v/2.3.5"}],"affected":[{"package":{"name":"chai-as-vite","ecosystem":"npm","purl":"pkg:npm/chai-as-vite"},"versions":["2.3.5"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"a23f968893bf0b765ee5ccfdc20f0e80e7727fe5","sha512_sri":"sha512-yUlFZVyH9eTjfz4IlVoIvDZexP6MQF2SbG/Nv/DjGsUPtThyCLyOdh7jFyobRISEqceNKEMIqAW4dS7CKowK1A=="},"filename":"chai-as-vite-2.3.5.tgz"}],"evidence_files":[{"sha256":"e5e2163fdafce48f59ac0fad8e8b98b5eaffa45e3978b18d442480b7758f6c6d","tlsh":"b311c08e61fc100c006152e5b62f14116021e4273d8ad5e877cc83871f9567f6d536ef","path":"lib/initializeCaller.js"},{"tlsh":"00019c60de788e2300ed25825c2a064376618c139928fc1933d7512d0f9d4bf01bf21d","path":"package.json","sha256":"fb8693f2fbcf5000945f5b90d4cde67ba0751d8c845a5ce2aa3744b07ceb0ee0"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-vite/MAL-2026-4514.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}