chai-beta is a malicious npm package that when imported downloads a C2 dropper from https://jsonkeeper[.]com/b/XRGF3 and executes it (similar to malware in to chai-await-test).
-= Per source details. Do not edit below this line.=-
The package chai-beta was found to contain malicious code.
{
"iocs": {
"urls": [
"https://jsonkeeper.com/b/XRGF3"
]
},
"malicious-packages-origins": [
{
"import_time": "2026-04-23T20:49:04.575344839Z",
"modified_time": "2026-04-23T20:43:56Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "b57727c6a080ac8eccf4106639fc8fceab20fd4fb96142c8a8cb9b68422d4867",
"source": "amazon-inspector"
},
{
"id": "RLMA-2026-05004",
"import_time": "2026-07-09T09:16:23.319457296Z",
"modified_time": "2026-07-07T12:43:37Z",
"sha256": "3eb41b2c6b5a301a28377d83c35161308b92697cce0171d2a780702899796fe8",
"source": "reversing-labs",
"versions": [
"1.1.9"
]
},
{
"id": "RLUA-2026-06134",
"import_time": "2026-09-01T11:17:59.789780216Z",
"modified_time": "2026-08-24T16:43:45Z",
"sha256": "d397c0c1cf7127cd166f25afdebdfac6261ebc36e5fa055a1350c000acec3a73",
"source": "reversing-labs"
}
]
}