BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ViteVenom: 7 Malicious npm Packages Target Vite Ecosystem

Malicious npm packages target Vite ecosystem in blockchain-based supply chain attack.

  • Researchers at Checkmarx uncovered the ViteVenom campaign, a software supply chain attack using seven malicious npm packages targeting the Vite frontend tooling ecosystem.
  • The attack, attributed to the threat actor SuccessKey, repurposes the ChainVeil malware’s blockchain-based command-and-control infrastructure across Tron, Aptos, and Binance Smart Chain.
  • The malicious packages were published to npm between June 29 and July 3, 2026, with over 2,400 total downloads, and execute a remote access trojan upon code import.

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack orchestrated by a threat actor named SuccessKey. The campaign, codenamed ViteVenom by Checkmarx, expands upon the previously observed ChainVeil malware, which utilized a blockchain-based command-and-control (C2) infrastructure spanning Tron, Aptos, and Binance Smart Chain.

- Advertisement -

This iteration specifically focuses on developers building applications with the Vite build tool. The malicious packages, published between June 29 and July 3, 2026, include @uw010010/vite-tree and @vite-tab/tab, among others, according to a Checkmarx analysis.

Activity linked to SuccessKey has been detected as far back as February 27, 2026, when associated cryptocurrency wallets were activated. Unlike the ChainVeil campaign’s unscoped typosquats, ViteVenom uses scoped package names to impersonate the legitimate “@vitejs/*” namespace.

The malicious code acts as a loader by querying the Tron blockchain for the latest transaction from the attacker’s wallet to obtain a Binance Smart Chain transaction hash. The attacker subsequently retrieves and decrypts the final payload using a hard-coded key, delivering a remote access trojan capable of reverse shell, credential harvesting, and file exfiltration.

Checkmarx researcher Pavan Gudimalla explained that “this tactic makes disabling or destroying the C2 infrastructure extremely difficult.” Users who have installed any of the identified packages are advised to remove them immediately, audit dependencies, and rotate all credentials.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

US Senate Delays Crypto Clarity Act Vote Until September

The U.S. Senate will not vote on the Clarity Act before its August recess,...

Trump could net big tax windfall from crypto ethics plan

A bipartisan ethics proposal tied to a crypto market structure bill includes a tax-deferral...

Musk’s Terafab: 50x Pentagon, $16.8B, 3,000 jobs

Elon Musk outlined Terafab’s massive scale, saying the Texas semiconductor complex will be 50...

MARA swings to $611M loss despite record Bitcoin production

MARA swung to a net loss of $611.3 million in Q2 2026, driven by...

SEC Bought Airline Ticket Data Without Warrant, Docs Show

The SEC purchased access to a global airline ticketing database with over 1 billion...

Must Read

The Best Bitcoin Casinos of 2025: An Expert’s Data-Driven Guide

Top 3 Bitcoin Casinos - Quick Comparison ...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading