-= Per source details. Do not edit below this line.=-
The package masquerades as the pino logging library (README badges and lib/ contents mimic pino) but ships a dropper at lib/initializeCaller.js. A self-executing IIFE POSTs the full process.env object to a base64-concealed endpoint that decodes to https://ipcheck-hashed.vercel.app/api/auth/b4dadd6a26d820d08596, using an 'x-secret-header: secret' header, and then passes the HTTP response body to new Function('require', response.data) with require handed in — executing attacker-returned JavaScript in the installer's Node process. The transmitted payload is the entire environment (not a single named variable), which on developer and CI machines typically includes NPM_TOKEN, GITHUB_TOKEN, AWS_* credentials, and other CI secrets. The destination URL is stored base64-encoded to conceal it from casual inspection, and the typosquat-style package name together with pino-themed documentation form a cover story for the dropper.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020896",
"import_time": "2026-10-04T23:16:31.010134339Z",
"modified_time": "2026-10-04T23:15:58Z",
"sha256": "af5e91a44a2eb0773df19fce2096660c285bafbe846a5f09d8bb25ff0eba22b2",
"source": "amazon-inspector",
"versions": [
"1.4.7"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "lib/initializeCaller.js",
"sha256": "266ef59f0542299b456e1d925e6c2c7f8db3b184ea9ca71e36bc037001a6d4f6",
"tlsh": "51f0874d34b61036426e58e1bb1b54565403f56137c0d855f2cd536b0f4ed4df6636d4"
},
{
"path": "README.md",
"sha256": "8d661906d9e11b78d198fa30905d0a17a924f595647207c46b93f530da78f914",
"tlsh": "0a5195a742f46f6e4b6700f1a2c275a9ef1f931cbb69606ddc98912d031d897813250a"
}
],
"package_integrity": [
{
"filename": "chai-as-testmode-1.4.7.tgz",
"hashes": {
"sha1": "b217e9d4b7073264c8d0ed24220a95c731f94e5a",
"sha512_sri": "sha512-c9AByd/sn28GWUdQmYZVtmQIz7uNgrvPLez4EYiA2TJV07skpQnH7dscjRwoVhed9LzuxrT3cDLEkXDzwLEhzw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-testmode/MAL-2026-17473.json"