Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
ID: 225219ac-b3cb-5614-8196-f1b89dee6603
STIX ID: report--225219ac-b3cb-5614-8196-f1b89dee6603
Feed Name: CosmicBytez Labs
ViteVenom is a supply-chain campaign identified by Checkmarx in which seven typosquatted npm packages targeting the Vite ecosystem install a RAT via postinstall scripts and use blockchain transactions as a resilient C2 channel; the RAT can exfiltrate source code and credentials, provide remote shell access, and achieve persistence. The campaign is attributed to the financially motivated ChainVeil actor and mitigations include dependency auditing, disabling postinstall scripts where appropriate, private registries/allowlisting, and immediate incident response if compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
