logo

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

ID: 225219ac-b3cb-5614-8196-f1b89dee6603

STIX ID: report--225219ac-b3cb-5614-8196-f1b89dee6603

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-17

Date Updated: 2026-07-18

...
...

ViteVenom is a supply-chain campaign identified by Checkmarx in which seven typosquatted npm packages targeting the Vite ecosystem install a RAT via postinstall scripts and use blockchain transactions as a resilient C2 channel; the RAT can exfiltrate source code and credentials, provide remote shell access, and achieve persistence. The campaign is attributed to the financially motivated ChainVeil actor and mitigations include dependency auditing, disabling postinstall scripts where appropriate, private registries/allowlisting, and immediate incident response if compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.