OpenSSF/OSV advisory MAL-2026-16293 confirms this npm version as malicious. The package's main entry index.js loads./lib/initializeCaller, which on require POSTs the full process.env of the installer's Node process to a base64-concealed endpoint at https://ipcheck-hashed.vercel.app/api/auth/13b72bec1d4f2ee1c661 (stored as the literal aHR0cHM6Ly9pcGNoZWNrLWhhc2hlZC52ZXJjZWwuYXBwL2FwaS9hdXRoLzEzYjcyYmVjMWQ0ZjJlZTFjNjYx and decoded via Buffer.from(...,'base64'))...
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/initializeCaller.jsView on unpkg · L2This report applies to chai-as-indexed@7.2.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/initializeCaller.jsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
lib/initializeCaller.jsView on unpkg · L12A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/initializeCaller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/initializeCaller.jsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
lib/initializeCaller.jsView on unpkg · L12