MAL-2026-17473

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-testmode/MAL-2026-17473.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17473
Published
2026-10-04T23:15:58Z
Modified
2026-10-04T23:30:04Z
Summary
Malicious code in chai-as-testmode (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (af5e91a44a2eb0773df19fce2096660c285bafbe846a5f09d8bb25ff0eba22b2)

The package masquerades as the pino logging library (README badges and lib/ contents mimic pino) but ships a dropper at lib/initializeCaller.js. A self-executing IIFE POSTs the full process.env object to a base64-concealed endpoint that decodes to https://ipcheck-hashed.vercel.app/api/auth/b4dadd6a26d820d08596, using an 'x-secret-header: secret' header, and then passes the HTTP response body to new Function('require', response.data) with require handed in — executing attacker-returned JavaScript in the installer's Node process. The transmitted payload is the entire environment (not a single named variable), which on developer and CI machines typically includes NPM_TOKEN, GITHUB_TOKEN, AWS_* credentials, and other CI secrets. The destination URL is stored base64-encoded to conceal it from casual inspection, and the typosquat-style package name together with pino-themed documentation form a cover story for the dropper.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020896",
            "import_time":  "2026-10-04T23:16:31.010134339Z",
            "modified_time":  "2026-10-04T23:15:58Z",
            "sha256":  "af5e91a44a2eb0773df19fce2096660c285bafbe846a5f09d8bb25ff0eba22b2",
            "source":  "amazon-inspector",
            "versions":  [
                "1.4.7"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / chai-as-testmode

Package

Name
chai-as-testmode
View open source insights on deps.dev
Purl
pkg:npm/chai-as-testmode

Affected ranges

Affected versions

1.*
1.4.7

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "lib/initializeCaller.js",
            "sha256":  "266ef59f0542299b456e1d925e6c2c7f8db3b184ea9ca71e36bc037001a6d4f6",
            "tlsh":  "51f0874d34b61036426e58e1bb1b54565403f56137c0d855f2cd536b0f4ed4df6636d4"
        },
        {
            "path":  "README.md",
            "sha256":  "8d661906d9e11b78d198fa30905d0a17a924f595647207c46b93f530da78f914",
            "tlsh":  "0a5195a742f46f6e4b6700f1a2c275a9ef1f931cbb69606ddc98912d031d897813250a"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "chai-as-testmode-1.4.7.tgz",
            "hashes":  {
                "sha1":  "b217e9d4b7073264c8d0ed24220a95c731f94e5a",
                "sha512_sri":  "sha512-c9AByd/sn28GWUdQmYZVtmQIz7uNgrvPLez4EYiA2TJV07skpQnH7dscjRwoVhed9LzuxrT3cDLEkXDzwLEhzw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-testmode/MAL-2026-17473.json"