VDB
EN

MAL-2026-13692

Malicious code in chai-jsonss (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (3b1fff32102bc74783cae571646ec0fd68b14c614b35a63badd814a64caa3b67) On import, index.js invokes postCallers() which resolves a base64-encoded URL stored in lib/const.js (decoding to https://1uznbx.s.gy/7xdQmt), GETs the response via axios, base64-decodes response.data.model, and passes it to new Function(require) — executing attacker-controlled JavaScript in-process. The destination is hidden as a DEV_API_KEY field on a fake process.env-shaped local module, and the payload URL is a shortlink to a mutable remote resource. The package name resembles chai but its main entry contains no chai-related functionality; the only import-time behavior is fetch-and-eval of remote code.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / chai-jsonss

No fixed version published yet for chai-jsonss (npm). Pin to a known-safe version or switch to an alternative.

참고