Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-17321 confirms this npm version as malicious. chaienv@1.0.2 is published as a small Chai environment helper, but its index.js unconditionally loads lib/config.js at require() time via `const { config } = require('./lib/config')`. lib/config.js is a 4,454,290-byte single-line module packed with obfuscator.io (RC4-decoded string array of roughly 26,000 entries), with no relation to the trivial no-op middleware the README advertises...
This report applies to chaienv@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.