-= Per source details. Do not edit below this line.=-
The package presents itself as a Chai logging plugin but its main entry index.js requires ./lib/query.js, a ~4 MB obfuscator.io-encoded module (23,868-entry rotated string array, T/j decoder wrappers, hex-property indirection) that executes at the top level as soon as the package is required. The remaining files under lib/ (proto.js, levels.js, tools.js, etc.) are verbatim copies of pino source, unrelated to the advertised Chai plugin API — a cover story around the obfuscated blob. package.json declares axios ^1.10.0 as a runtime dependency, and the only reference to axios in the shipped code is inside the obfuscated body of lib/query.js, giving the payload an HTTP client whose destination is reconstructed at runtime from the rotated string array. Author metadata points to jsonspack.com, unrelated to Chai or pino. The combination of import-time execution of a heavily obfuscated payload, a mismatched cover story, copied third-party source used as filler, and an HTTP client declared only for use inside the obfuscated code is the canonical npm credential/data-stealer shape.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020288",
"import_time": "2026-09-22T14:19:07.85130445Z",
"modified_time": "2026-09-22T13:58:43Z",
"sha256": "566e54855d730e8555b93da4f8ea81faba72645079a7adcc3a05ea8bf8ad8ee6",
"source": "amazon-inspector",
"versions": [
"3.0.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "lib/query.js",
"sha256": "df4970a67c9caae5dd2e4603ea726f7624a4c17bb197a1039985a10ff9b56923",
"tlsh": "f016818d5685d42381cc2793be057ae9b17ae96684cca447ff74bf1c69bc41bc2a0ed0"
},
{
"path": "package.json",
"sha256": "8a171b5efc6c849d971fd40ffd68d887b371cbe1c27e794044d80316862321b7",
"tlsh": "23019920debc9e2300ed25525c2a0603ba658c579628fc2932dba12c0fad5ff01ff21d"
}
],
"package_integrity": [
{
"filename": "chai-logger-3.0.2.tgz",
"hashes": {
"sha1": "2a2b9aa551c1dc15b11e429c6a3eaf2d78ff392a",
"sha512_sri": "sha512-uWz/DmRni5nCphVk4CT+Il5BE2u8ekz8SEe54KN/WgJVNlXknS3ILTSWN/zLPs9jUNP3d7bYp5edV7f8p6KKGA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-logger/MAL-2026-16380.json"