MAL-2026-4514

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-vite/MAL-2026-4514.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-4514
Published
2026-05-21T19:07:50Z
Modified
2026-05-26T06:02:19Z
Summary
Malicious code in chai-as-vite (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (b7096b7b983ae63f8e59f9e047440547c9536f6c4c9da0ac46909b91a9d4e10e)

The package masquerades as a pino-style logger (exports module.exports.pino = middleware, keywords fast,logger,stream,json, lib filenames proto.js, redaction.js, multistream.js, transport.js) under a name evoking chai/vite tooling. When a consumer requires the package and invokes the exported middleware, lib/initializeCaller.js is launched as a detached node child process. That script defines a local process shadow whose env holds base64 strings (DEV_API_KEY, DEV_SECRET_KEY, DEV_SECRET_VALUE), atob-decodes them to recover the URL https://purple-kelila-79.tiiny.site/data.json and the header x-secret-key: _, fetches the response via axios, then executes the response body with new Function.constructor('require', response)(require) — full arbitrary code execution with require access on the installer's machine, with retry. The destination is an anonymous, mutable tiiny.site host with no version pinning and no integrity check, so the operator can rotate the delivered payload at will. Base64-encoded URL and header values, the fake process.env shadow, and the detached child-process launch are intentional evasion.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-003997",
            "import_time": "2026-05-26T05:51:44.132343559Z",
            "modified_time": "2026-05-21T19:07:50Z",
            "sha256": "b7096b7b983ae63f8e59f9e047440547c9536f6c4c9da0ac46909b91a9d4e10e",
            "source": "amazon-inspector",
            "versions": [
                "2.3.5"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / chai-as-vite

Package

Affected ranges

Affected versions

2.*
2.3.5

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "lib/initializeCaller.js",
            "sha256": "e5e2163fdafce48f59ac0fad8e8b98b5eaffa45e3978b18d442480b7758f6c6d",
            "tlsh": "b311c08e61fc100c006152e5b62f14116021e4273d8ad5e877cc83871f9567f6d536ef"
        },
        {
            "path": "package.json",
            "sha256": "fb8693f2fbcf5000945f5b90d4cde67ba0751d8c845a5ce2aa3744b07ceb0ee0",
            "tlsh": "00019c60de788e2300ed25825c2a064376618c139928fc1933d7512d0f9d4bf01bf21d"
        }
    ],
    "package_integrity": [
        {
            "filename": "chai-as-vite-2.3.5.tgz",
            "hashes": {
                "sha1": "a23f968893bf0b765ee5ccfdc20f0e80e7727fe5",
                "sha512_sri": "sha512-yUlFZVyH9eTjfz4IlVoIvDZexP6MQF2SbG/Nv/DjGsUPtThyCLyOdh7jFyobRISEqceNKEMIqAW4dS7CKowK1A=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/chai-as-vite/MAL-2026-4514.json"