Sequel to ChainVeil npm Malware Targets Vite Ecosystem
ID: 58126d67-59f0-5baf-9425-a5f4fd5ed7ea
STIX ID: report--58126d67-59f0-5baf-9425-a5f4fd5ed7ea
Feed Name: Checkmarx Zero
Checkmarx Zero describes 'ViteVenom', a cluster of seven malicious scoped npm packages published in mid-2026 that target the Vite ecosystem to deliver a 77KB RAT; the campaign reuses Tier-2 blockchain wallets, identical XOR keys, and C2 infrastructure previously seen in the ChainVeil campaign, making the attack highly resilient and linking both clusters to a likely single operator. The report includes in-depth technical analysis of the obfuscated loader (bin/vite.js), the multi-tier Tron→Aptos→BSC blockchain C2 resolution, direct HTTP fallback (detached child process), full IoCs (C2 IPs, Tron/Aptos addresses, BSC tx hashes, XOR keys), mitigation steps, and detection hunts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
