MAL-2026-14491

    Dashboard / Malicious Package / MAL-2026-14491

    MAL-2026-14491

    Published: 25 Aug 2026Last Modified: 25 Aug 2026

    Summary: Malicious code in chai-as-otc (npm)

    Details: Source: amazon-inspector (cf771adc4f92ba0d79ea56bdcc1e42db57d1bc7421f0dadb0544f619e16b5ca1) On module load, lib/initializeCaller.js (required from index.js) runs an IIFE that POSTs the full process.env to a base64-obfuscated endpoint decoding to https://ipcheck-hashed.vercel.app/api/auth/6c1d60d35852ef0c05df, then passes the HTTP response body to new Function("require", response.data) and invokes it with require, yielding arbitrary Node code execution on the installer's host at load time. The package is framed as a pino-style logging middleware with a 'Successfully synced!' cover string, but the actual behavior is a covert credential harvester and remote loader.

    Affected packages

    Package

    Name: chai-as-otc

    Purl: pkg:npm/chai-as-otc

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.5
    MAL-2026-14491 | CVE-DB