chai-check-errornpm
Malicious code in chai-check-error (npm) Remove it immediately and rotate any exposed credentials.
What this malware does
[email protected] impersonates the legitimate chaijs/check-error utility (copied README, author metadata, repository URL, and exported API surface) and adds a malicious payload. package.json declares "postinstall": "node index.js", and index.js calls _initMsgCache() at module top level so the same code path also fires on every require(). _initMsgCache derives an AES-256-CBC key/IV from a hardcoded byte array _d mixed via a _sbox(0x9E3779B1,...) routine, decrypts a 165-byte ciphertext into an HTTPS URL, fetches that URL with require('https').get(...), parses the JSON response, and executes the cookie field as JavaScript through new Function('require', mod)(require). The destination URL is intentionally obfuscated and the surrounding comments frame the routine as a benign "internal message cache" / "locale-aware message formatting" feature, but getMessage never reads _msgCache — the cache framing is cover-story. Any developer who installs this package — whether intentionally or by confusing it with chai's check-error — runs arbitrary attacker-controlled JavaScript under their Node process at install time and again on every import.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
TyposquatFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for chai-check-error (5 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging chai-check-error across your stack and pipelines.
If you installed it — respond
chai-check-error is a typosquat — you almost certainly intended a legitimately-named package. Remove chai-check-error, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.
Did it already run?
If chai-check-error was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks chai-check-error before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks chai-check-error-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.