Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
ID: f4cce1dc-b94b-5113-aa4d-f9ad01eb3186
STIX ID: report--f4cce1dc-b94b-5113-aa4d-f9ad01eb3186
Feed Name: The Hacker News
**ViteVenom supply-chain malware campaign:** Checkmarx researchers identified seven malicious npm packages impersonating the @vitejs namespace that act as import-time loaders for a RAT, using multi-tier blockchain (Tron, Aptos, BSC) and HTTP fallback C2 to fetch encrypted payloads and configuration; the activity is linked to the actor SuccessKey and reuses infrastructure from the earlier ChainVeil operations, with guidance to remove packages, audit dependencies, rotate credentials, and check shell initialization files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
