chai-chain-async

MAL-2026-386

npmmalware1/21/2026
Description

Malicious code in chai-chain-async (npm)

Indicators of Compromise
SHA256 Hashes (3)
a3404961b3edc416f501bf5ec175f0bbb95a188e9f1210305c9e37783e626555
d3340d37485bf0cbe47f2378b96588e8afadc83635bef93d108730ea72ab8f78
4adf9b46f9cd226903465635ffcb9baf6a98f18f83af839cbb08fefd709e3a64
Details
Ecosystemnpm
Attack Typemalware
Published1/21/2026
Affected Versions
0
Aliases
GHSA-9fmw-9xvf-xpqq
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001