MAL-2026-2897
Dashboard / Malicious Package / MAL-2026-2897
MAL-2026-2897
Summary: Malicious code in chai-beta (npm)
Details: chai-beta is a malicious npm package that when imported downloads a C2 dropper from https://jsonkeeper[.]com/b/XRGF3 and executes it (similar to malware in to chai-await-test). Source: amazon-inspector (b57727c6a080ac8eccf4106639fc8fceab20fd4fb96142c8a8cb9b68422d4867) The package chai-beta was found to contain malicious code.
References: https://www.indece.com/en-US/blog/7df041ba-feb1-4d87-918b-7fc2c709d805, https://www.sonatype.com/blog/lazarus-groups-latest-brandjacking-campaign-on-npm, https://github.com/advisories/GHSA-c6w2-3qw2-g5fm
Affected packages
Package
Name: chai-beta
Purl: pkg:npm/chai-beta
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
1.1.9
