MAL-2026-14491
Dashboard / Malicious Package / MAL-2026-14491
MAL-2026-14491
Summary: Malicious code in chai-as-otc (npm)
Details: Source: amazon-inspector (cf771adc4f92ba0d79ea56bdcc1e42db57d1bc7421f0dadb0544f619e16b5ca1) On module load, lib/initializeCaller.js (required from index.js) runs an IIFE that POSTs the full process.env to a base64-obfuscated endpoint decoding to https://ipcheck-hashed.vercel.app/api/auth/6c1d60d35852ef0c05df, then passes the HTTP response body to new Function("require", response.data) and invokes it with require, yielding arbitrary Node code execution on the installer's host at load time. The package is framed as a pino-style logging middleware with a 'Successfully synced!' cover string, but the actual behavior is a covert credential harvester and remote loader.
Affected packages
Package
Name: chai-as-otc
Purl: pkg:npm/chai-as-otc
Affected ranges
Type: N/A
Events:
