Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

chai-promised-testnpm

Advisory published Updated

chai-promised-test is a confirmed malicious npm package (MAL-2026-10052) that opens a backdoor for remote access (malicious version 1.3.5). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in chai-promised-test (npm)

MAL-2026-10052
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall chai-promised-test

What this malware does

Package masquerades as a chai-as-promised plugin / pino logger (README and exports copied from pino, including module.exports.pino = middleware) but on use spawns a detached Node process running lib/caller.js, which fetches a string from https://jsonkeeper.com/b/EXSIF and executes it via new Function.constructor("require", s)(require). The fetched code runs with full Node privileges (require, fs, child_process, network). The C2 URL and request headers are concealed by shadowing the local process object with fields named DEV_API_KEY / DEV_SECRET_KEY / DEV_SECRET_VALUE, and lib/const.js carries base64-encoded equivalents that decode to a second jsonkeeper.com paste and the header name x-secret-key. The remote paste is mutable and attacker-controlled, allowing arbitrary code execution on the installer's machine. Identity confusion with chai-as-promised / pino indicates the package exists to be installed by mistake.

Malicious versions

1 flagged
1.3.5

Indicators of compromise (SHA-256)

1ddaac3e93ed2e5d968816cf3153b2ab1878580bb9ee65ec3ec1acdca41dc018

Detection & response playbook

Backdoor / remote access
  1. Find it

    Search your lockfiles and build artifacts for chai-promised-test (version 1.3.5).

  2. If you installed it — respond

    chai-promised-test establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.

  3. Did it already run?

    If chai-promised-test was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. chai-promised-test on npm has been identified as a malicious package (version 1.3.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-009134

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks chai-promised-test-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.

Explore

chai-promised-test (npm) malicious package — MAL-2026-10052 | O3 Security