plugin-react-vite@2.1.2
Malicious code in plugin-react-vite (npm)
Analysis
plugin-react-vite@2.1.2 is a remote-code-execution dropper. Its main entry point (index.js) fetches a payload from hxxp://31[.]97[.]137[.]157:45000/icons/116 (raw IP, non-standard port, custom header "bearrtoken: logo") and executes the response's `credits` field via the Function constructor with full Node.js context (require, process, Buffer, module), so the actual malicious code is served remotely and never shipped in the package. The package name impersonates the Vite React plugin ecosystem and its README is a mismatched copy-paste from an unrelated package. C2: 31[.]97[.]137[.]157:45000, path /icons/116.
- analyzed by
- Leitwacht
- first seen
- Aug 18, 2026, 05:32 PM
- analyzed
- Aug 18, 2026, 05:32 PM
Related advisories
- config-helper-kit@1.3.2
- space-items@1.0.0
- tailwind-extension-kit@1.3.2
- core-tailwindcss-utility@3.7.1
- runtime-health@1.0.1
- rand-tx-sdk@1.0.6
- tyepescript-core@1.0.0
- typecript-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.