Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

chai-await-domnpm

Advisory published Updated

chai-await-dom is a confirmed malicious npm package (MAL-2026-10049) that opens a backdoor for remote access (malicious version 1.3.7). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in chai-await-dom (npm)

MAL-2026-10049
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall chai-await-dom

What this malware does

The package impersonates a pino-style logger API but its exported middleware spawns a detached Node child process that runs lib/caller.js. caller.js retrieves a JavaScript payload from https://jsonkeeper.com/b/BPB86 (an anonymous paste-style host) and executes it in-process via new Function.constructor('require', s)(require), granting the remote host arbitrary code execution with the installer's Node privileges. lib/const.js stores a base64-encoded sibling URL (https://jsonkeeper.com/b/ZK45J decoded from aHR0cHM6Ly9qc29ua2VlcGVyLmNvbS9iL1pLNDVK), deliberately obfuscating the C2 destination. The package name (chai-await-dom) does not match its actual behavior or its impersonated logger API surface, consistent with a namespace-abuse lure carrying a remote-code-execution payload.

Malicious versions

1 flagged
1.3.7

Indicators of compromise (SHA-256)

e78d8b4da2e781df4437569123ba3913c3f0135bbef66addaa5766a109fdd98b
d2bbe277b40e8c1fa93ac4c7818407fc8a707287daa7cdae7bce3ac4268ed3c5

Detection & response playbook

Backdoor / remote access
  1. Find it

    Search your lockfiles and build artifacts for chai-await-dom (version 1.3.7).

  2. If you installed it — respond

    chai-await-dom establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.

  3. Did it already run?

    If chai-await-dom was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. chai-await-dom on npm has been identified as a malicious package (version 1.3.7 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-009141RLMA-2026-06133

References

Credits

  • Amazon Inspector · finder
  • ReversingLabs · finder

Detect & block this

O3 blocks chai-await-dom-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.

Explore

chai-await-dom (npm) malicious package — MAL-2026-10049 | O3 Security