logo

Sequel to ChainVeil npm Malware Targets Vite Ecosystem

ID: 58126d67-59f0-5baf-9425-a5f4fd5ed7ea

STIX ID: report--58126d67-59f0-5baf-9425-a5f4fd5ed7ea

Feed Name: Checkmarx Zero

Threat Score
75/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: Pavan Gudimalla

...
...

Checkmarx Zero describes 'ViteVenom', a cluster of seven malicious scoped npm packages published in mid-2026 that target the Vite ecosystem to deliver a 77KB RAT; the campaign reuses Tier-2 blockchain wallets, identical XOR keys, and C2 infrastructure previously seen in the ChainVeil campaign, making the attack highly resilient and linking both clusters to a likely single operator. The report includes in-depth technical analysis of the obfuscated loader (bin/vite.js), the multi-tier Tron→Aptos→BSC blockchain C2 resolution, direct HTTP fallback (detached child process), full IoCs (C2 IPs, Tron/Aptos addresses, BSC tx hashes, XOR keys), mitigation steps, and detection hunts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.