Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

chai-as-bufferednpm

Advisory published Updated

chai-as-buffered is a confirmed malicious npm package (MAL-2026-10041) that opens a backdoor for remote access (malicious versions 3.7.24, 7.2.5). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in chai-as-buffered (npm)

MAL-2026-10041
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall chai-as-buffered

What this malware does

[email protected] is a typosquat lure (name resembles chai-as-promised; README and module exports impersonate the pino logger) whose actual behavior is a remote-payload dropper. lib/caller.js shadows process with a local object whose env holds base64-encoded constants for the C2 URL, header name, and header value, hiding the destination from review and from env scanning. When the exported middleware is invoked (e.g., via chai.use(...) or require('chai-as-buffered') wiring through the pino-styled export), the package base64-decodes the hidden URL (https://api.jsonstorage.net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/a179ea35-b962-4722-b3f1-e28316d1a44a), spawns a detached, stdio-ignored node./lib/caller.js child, fetches a JSON document from that mutable third-party blob, and passes the document's cookie field to Function.constructor('require', s) invoked with the live require. The fetched JavaScript executes with full require access on the installer's machine. The destination is an attacker-controlled mutable JSON store whose content can be changed at any time, giving the publisher arbitrary code execution against any environment that loads this package.

Malicious versions

2 flagged
3.7.247.2.5

Indicators of compromise (SHA-256)

3d136202d96267459c4bf3aaaf6c903d7bd2c491901b61dcf2f391a4612f951a
92a37028060f47639987506210a75d53d3667edc6318ac978198b684a3026569
2ecb1884d7e298d84e41c17c2ba0c868bd59f470d0aaffc52287b178315f2fad

Detection & response playbook

Backdoor / remote access
  1. Find it

    Search your lockfiles and build artifacts for chai-as-buffered (2 malicious versions).

  2. If you installed it — respond

    chai-as-buffered establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.

  3. Did it already run?

    If chai-as-buffered was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. chai-as-buffered on npm has been identified as a malicious package (versions 3.7.24, 7.2.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-009142RLMA-2026-06109IN-MAL-2026-020173

References

Credits

  • Amazon Inspector · finder
  • ReversingLabs · finder

Detect & block this

O3 blocks chai-as-buffered-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.

Explore

chai-as-buffered (npm) malicious package — MAL-2026-10041 | O3 Security