-= Per source details. Do not edit below this line.=-
On require, the package spawns a detached background node process running lib/initializeCaller.js. That script base64-decodes a hardcoded URL (https://tomato-brunhilda-40.tiiny.site/index.json), fetches JSON from it, and executes the returned cookie field through new Function.constructor('require', response)(require) — giving the remote payload full require access on the installer's host. The endpoint URL and request header key/value are hidden inside base64 strings assigned to a locally-shadowed process.env object and decoded via atob() at runtime, obfuscating the C2 destination. The package additionally impersonates two well-known libraries: the name chai-as-sharpened mimics chai-as-promised, and the README badges/links point to pino and pinojs/pino, using name confusion as the delivery vector. Import triggers unconditional RCE against any consumer.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-009125",
"import_time": "2026-07-09T16:20:43.156537114Z",
"modified_time": "2026-07-09T15:31:55Z",
"sha256": "854e8e5d81ba59ee1353535523ea62b29c07de8d6a5cc50745a471696d80576a",
"source": "amazon-inspector",
"versions": [
"7.0.9"
]
},
{
"id": "RLMA-2026-06127",
"import_time": "2026-09-01T11:17:28.208060801Z",
"modified_time": "2026-08-24T16:43:41Z",
"sha256": "70ae7a33ba961df24040a7de3948bc0e708324d662e5026b1a01e7e5465d064c",
"source": "reversing-labs",
"versions": [
"7.0.9"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "lib/initializeCaller.js",
"sha256": "23436f977c9bbe6d302f0f94e191b3dfd938e5a0417ec098d38b60b0ed0cb14f",
"tlsh": "9511c08e61fc200c046512e6b62f18126021e8673d86d5e47acc835b1f9567f7d936df"
},
{
"path": "README.md",
"sha256": "90faf284e6a0900143752f8e2cf753e7cf78b44175911cb8472bfb7ff2c778f6",
"tlsh": "7651976796e86fae5b6301b1a1c334b9ff1f931c7b6e506dec9c91381319997803114b"
}
],
"package_integrity": [
{
"filename": "chai-as-sharpened-7.0.9.tgz",
"hashes": {
"sha1": "214d67830292333e22d1eaa60e323622c64e46bc",
"sha512_sri": "sha512-UIPAVVArb6L5GSr+Odvcp0TGvz4ZQCVXuk1Hc/GJwWZTb+yv6bhYTEp8q2zBWAzaK8Td52IJuuNR2ee26qG7Rw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-sharpened/MAL-2026-10045.json"