Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

chai-as-alignnpm

Advisory published Updated

chai-as-align is a confirmed malicious npm package (MAL-2026-10039) that typosquats a legitimate package to trick installs (malicious version 7.1.0). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in chai-as-align (npm)

MAL-2026-10039
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall chai-as-align

What this malware does

The package presents itself as a testing/logging helper but its exported middleware factory spawns a detached background Node child that runs lib/initializeCaller.js. That script base64-decodes a hidden URL (https://amethyst-lorrin-26.tiiny.site/index.json) from a fake process.env stub, fetches its 'cookie' field over HTTPS with an 'x-secret-key' header, and executes the returned body via new Function.constructor('require', response) bound to the real require, in a retry loop. This yields full remote code execution on the installer's machine whenever the exported middleware is invoked. The destination is an anonymous file-hosting service (tiiny.site) whose contents are attacker-mutable. The package name closely resembles the popular chai-as-promised library, and its declared description/keywords do not match the shipped code, indicating typosquat delivery of the dropper. The detached+unref'd child with stdio ignored is used to hide the payload's activity from the consuming application.

Malicious versions

1 flagged
7.1.0

Indicators of compromise (SHA-256)

791f5dcd4f623d5301bc3abf922c5f0e4ff716017fe67d3673c778e9d31b0776
68e0cd5dd9417808ac7e6442656f3fd723ae6d94ad8666d473872abfbb3e099d

Detection & response playbook

Typosquat
  1. Find it

    Search your lockfiles and build artifacts for chai-as-align (version 7.1.0).

  2. If you installed it — respond

    chai-as-align is a typosquat — you almost certainly intended a legitimately-named package. Remove chai-as-align, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.

  3. Did it already run?

    If chai-as-align was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. chai-as-align on npm has been identified as a malicious package (version 7.1.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-009136RLMA-2026-06107

References

Credits

  • Amazon Inspector · finder
  • ReversingLabs · finder

Detect & block this

O3 blocks chai-as-align-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

chai-as-align (npm) malicious package — MAL-2026-10039 | O3 Security