element-plus-vite-cli@2.9.3
Malicious code in element-plus-vite-cli (npm)
Analysis
element-plus-vite-cli is a trojanized Vite CLI wrapper. Running its bin (or requiring the package) invokes tooling-bootstrap.cjs, which decodes an embedded base64 payload and drops it as tooling-api-runtime.mjs into ~/.gradle/daemon/, then spawns it as a detached background process that persists after the parent exits. The dropped agent is a remote-access trojan that beacons to the C2 server hxxps://npmjs[.]it[.]com/ (a typosquat of npmjs[.]com). It registers the host (hostname, username, OS, and a persistent agent id stored in ~/.gradle-cache/.aid) via POST /api/register, then polls GET /api/task/{agent_id} for commands. It can execute arbitrary shell commands (cmd.exe or /bin/sh), list directories, read and exfiltrate file contents to /api/file/{agent_id}/{task_id}, write files from base64 data, delete and move files, and list processes, reporting results to /api/result/{agent_id}. The implant only activates when the consuming project contains one of a hardcoded set of sentinel source files (e.g. src/api/cicade.js, src/views/orderCenter/orderCenter.vue).
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 08:52 AM
- analyzed
- Sep 16, 2026, 08:53 AM
Related advisories
- @baipiaojuntuan/reverseproxy-fm@1.0.9
- hydration-cls-ui@1.0.0
- hydration-ui-dim@1.0.0
- hydration-dim-kit@1.0.0
- @oss-core-eng/data-formatter@1.0.1
- kit-vim-map@1.0.0
- kit-map-streak@1.0.0
- streak-kit-map@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.