MAL-2026-1683

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-promised-tools/MAL-2026-1683.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-1683
Published
2026-03-18T12:43:22Z
Modified
2026-03-23T05:40:54.212213Z
Summary
Malicious code in chai-promised-tools (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (9a73df3d15a01155775fd64c754db5ed47ea65ad63281989810ee1f207cd23f9)

The package chai-promised-tools was found to contain malicious code.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2026-01187",
            "sha256": "87138e6760cd7a6f65f276814ca5d0b880f5408c47fdd44d6459ce939410b3ed",
            "import_time": "2026-03-19T12:18:40.697042785Z",
            "source": "reversing-labs",
            "modified_time": "2026-03-18T12:43:22Z",
            "versions": [
                "3.3.5"
            ]
        },
        {
            "import_time": "2026-03-23T05:14:25.651247757Z",
            "sha256": "9a73df3d15a01155775fd64c754db5ed47ea65ad63281989810ee1f207cd23f9",
            "source": "amazon-inspector",
            "modified_time": "2026-03-23T05:11:41Z",
            "versions": [
                "3.3.5"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / chai-promised-tools

Package

Name
chai-promised-tools
View open source insights on deps.dev
Purl
pkg:npm/chai-promised-tools

Affected ranges

Affected versions

3.*
3.3.5

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-promised-tools/MAL-2026-1683.json"