As cited
Copy frozen at (site build).
threat intel
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Researchers identified seven malicious npm packages targeting the Vite frontend build tool ecosystem. The attack, labeled ViteVenom, leverages a blockchain-based command-and-control infrastructure across multiple chains as part of a broader ChainVeil campaign.
Why it matters: JavaScript developers using Vite are at immediate risk of supply chain compromise through dependency installation; teams should audit npm dependencies and verify package sources.
- Source published
- First seen by Cybersecurity Tracker