OpenSSF/OSV advisory MAL-2026-16293 confirms this npm version as malicious. chai-as-indexed presents itself as a pino-compatible logger (package.json keywords fast/logger/stream/json, exports module.exports.pino, lib/* filenames mirror pino) but the exported middleware's only real action is to spawn a detached Node child that runs lib/caller.js. lib/caller.js hides its C2 behind a fake local `process.env` object whose values are base64 literals (DEV_API_KEY, DEV_SECRET_KEY,...
This report applies to chai-as-indexed@6.0.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.