Malicious code in express-chai (npm)
The express-chai npm package version 3.7.9 contains malicious code that impersonates an Express logger middleware. It fetches a remote JSON payload from a base64-obfuscated URL and executes code from the payload with full access to the Node.js require function and application context, enabling arbitrary code execution during middleware setup.
AI Analysis
Technical Summary
The express-chai package (version 3.7.9) masquerades as a legitimate Express logger middleware but includes a malicious component that decodes a base64-obfuscated URL to fetch a JSON payload from a remote server. It sends a base64-encoded secret key in the request header and extracts a 'cookie' field from the response, which it executes as code using the Function constructor with access to the local require function. This allows the remote operator to execute arbitrary code within the Node.js process that installs the middleware, compromising the host environment. The package uses naming and keywords to disguise itself as a known logging library, facilitating its distribution and installation.
Potential Impact
Successful installation and use of express-chai version 3.7.9 results in arbitrary code execution within the Node.js process, granting an attacker full access to the require function and the surrounding application context. This can lead to complete compromise of the application and potentially the host system running the Node.js process.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid installing or using express-chai version 3.7.9. Remove the package from any projects and replace it with a trusted alternative. Monitor for any unexpected network connections or code execution related to this package. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Malicious code in express-chai (npm)
Description
The express-chai npm package version 3.7.9 contains malicious code that impersonates an Express logger middleware. It fetches a remote JSON payload from a base64-obfuscated URL and executes code from the payload with full access to the Node.js require function and application context, enabling arbitrary code execution during middleware setup.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The express-chai package (version 3.7.9) masquerades as a legitimate Express logger middleware but includes a malicious component that decodes a base64-obfuscated URL to fetch a JSON payload from a remote server. It sends a base64-encoded secret key in the request header and extracts a 'cookie' field from the response, which it executes as code using the Function constructor with access to the local require function. This allows the remote operator to execute arbitrary code within the Node.js process that installs the middleware, compromising the host environment. The package uses naming and keywords to disguise itself as a known logging library, facilitating its distribution and installation.
Potential Impact
Successful installation and use of express-chai version 3.7.9 results in arbitrary code execution within the Node.js process, granting an attacker full access to the require function and the surrounding application context. This can lead to complete compromise of the application and potentially the host system running the Node.js process.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately avoid installing or using express-chai version 3.7.9. Remove the package from any projects and replace it with a trusted alternative. Monitor for any unexpected network connections or code execution related to this package. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13446
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a75744dbf8831d539d9b059
Added to database: 08/07/2026, 05:59:41 UTC
Last enriched: 08/07/2026, 06:12:21 UTC
Last updated: 08/07/2026, 06:12:21 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.