Hostile 100% javascript Download

chai-assert-kit 3.8.1

Obfuscated dropper spawns hidden child process

Obfuscated HTTP response executes as JavaScriptPackage import detaches remote-code loader

Also flagged by osv (MAL-2026-6221: Malicious code in chai-assert-kit (npm)) +1 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.