OpenSSF/OSV advisory MAL-2026-10041 confirms this npm version as malicious. chai-as-buffered@3.7.24 is a typosquat lure (name resembles chai-as-promised; README and module exports impersonate the pino logger) whose actual behavior is a remote-payload dropper. lib/caller.js shadows `process` with a local object whose `env` holds base64-encoded constants for the C2 URL, header name, and header value, hiding the destination from review and from env scanning...
This report applies to chai-as-buffered@3.7.24.
3.7.24, 7.2.5
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.