Malicious code in chai-tracker (npm)
The chai-tracker npm package contains malicious code that executes arbitrary code on the host system when the package is loaded. It mimics the legitimate chai-spies package but depends on an attacker-controlled package named dbconnectify pinned to 'latest'. Upon loading, chai-tracker spawns a detached child process that runs code from dbconnectify, allowing silent execution of arbitrary commands. This malicious behavior is disguised within chai method registration, making it difficult to detect during normal use.
AI Analysis
Technical Summary
chai-tracker is a malicious npm package impersonating chai-spies by matching its name, README, and keywords. It declares peerDependencies on an attacker-controlled package dbconnectify pinned to 'latest' and axios. When a consumer calls chai.use(require('chai-tracker')), the exported plugin function invokes a helper named assertConnection(), which does not perform assertions but instead spawns a detached child process executing inline code that requires dbconnectify and calls a method on it. Because dbconnectify is attacker-controlled and unversioned, arbitrary code executes on the installer's host silently with stdio ignored. The malicious code is concealed within the chai Assertion method registration process.
Potential Impact
Arbitrary code execution occurs on the host system at plugin load time, allowing attackers to run any code with the privileges of the user installing or running chai-tracker. The execution is silent and detached, making detection difficult. This can lead to compromise of the host environment, data theft, or further malicious activities.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing or using the chai-tracker package. Audit dependencies carefully and verify package authenticity before use. Consider removing chai-tracker from projects and replacing it with legitimate alternatives such as chai-spies. Monitor for any unexpected child processes spawned by development tools.
Malicious code in chai-tracker (npm)
Description
The chai-tracker npm package contains malicious code that executes arbitrary code on the host system when the package is loaded. It mimics the legitimate chai-spies package but depends on an attacker-controlled package named dbconnectify pinned to 'latest'. Upon loading, chai-tracker spawns a detached child process that runs code from dbconnectify, allowing silent execution of arbitrary commands. This malicious behavior is disguised within chai method registration, making it difficult to detect during normal use.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
chai-tracker is a malicious npm package impersonating chai-spies by matching its name, README, and keywords. It declares peerDependencies on an attacker-controlled package dbconnectify pinned to 'latest' and axios. When a consumer calls chai.use(require('chai-tracker')), the exported plugin function invokes a helper named assertConnection(), which does not perform assertions but instead spawns a detached child process executing inline code that requires dbconnectify and calls a method on it. Because dbconnectify is attacker-controlled and unversioned, arbitrary code executes on the installer's host silently with stdio ignored. The malicious code is concealed within the chai Assertion method registration process.
Potential Impact
Arbitrary code execution occurs on the host system at plugin load time, allowing attackers to run any code with the privileges of the user installing or running chai-tracker. The execution is silent and detached, making detection difficult. This can lead to compromise of the host environment, data theft, or further malicious activities.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid installing or using the chai-tracker package. Audit dependencies carefully and verify package authenticity before use. Consider removing chai-tracker from projects and replacing it with legitimate alternatives such as chai-spies. Monitor for any unexpected child processes spawned by development tools.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13704
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a79f0c4bf8831d539f5dc83
Added to database: 08/10/2026, 15:39:48 UTC
Last enriched: 08/10/2026, 15:41:56 UTC
Last updated: 08/10/2026, 15:42:20 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.