LWA-2026-12170 MAL-2026-16331 ↗ confirmed malware

element-plus-vite-cli@2.9.3

Malicious code in element-plus-vite-cli (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1082 · System Information DiscoveryT1547 · Boot or Logon Autostart Execution

Analysis

element-plus-vite-cli is a trojanized Vite CLI wrapper. Running its bin (or requiring the package) invokes tooling-bootstrap.cjs, which decodes an embedded base64 payload and drops it as tooling-api-runtime.mjs into ~/.gradle/daemon/, then spawns it as a detached background process that persists after the parent exits. The dropped agent is a remote-access trojan that beacons to the C2 server hxxps://npmjs[.]it[.]com/ (a typosquat of npmjs[.]com). It registers the host (hostname, username, OS, and a persistent agent id stored in ~/.gradle-cache/.aid) via POST /api/register, then polls GET /api/task/{agent_id} for commands. It can execute arbitrary shell commands (cmd.exe or /bin/sh), list directories, read and exfiltrate file contents to /api/file/{agent_id}/{task_id}, write files from base64 data, delete and move files, and list processes, reporting results to /api/result/{agent_id}. The implant only activates when the consuming project contains one of a hardcoded set of sentinel source files (e.g. src/api/cicade.js, src/views/orderCenter/orderCenter.vue).

analyzed by
Leitwacht
first seen
Sep 16, 2026, 08:52 AM
analyzed
Sep 16, 2026, 08:53 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.