@vitemirrorte/element-plus-vite-cli@2.9.1
Malicious code in @vitemirrorte/element-plus-vite-cli (npm)
Analysis
The postinstall hook of this scoped package (a combosquat of the element-plus-vite-cli tool) checks whether the installing project matches a hardcoded target workspace (package name mall4cloud-react with exact content digests). When it matches, the hook decrypts an AES-256-GCM-encrypted agent runtime (key derived from the workspace fingerprint) and launches it as a detached background process under ~/.gradle/caches/transforms-3/8.7/instrumented/.../instrumentation-agent-runtime.mjs. The agent registers the host (hostname, username, OS) to hxxps://npmjs[.]it[.]com/api/register, then polls hxxps://npmjs[.]it[.]com/api/task/{agentId} every ~5s for commands. It supports arbitrary shell execution (exec), directory listing (ls), file exfiltration to hxxps://npmjs[.]it[.]com/api/file/{agentId}/{taskId}, file upload/write, file deletion, process listing, and file moves. The C2 base URL can be overridden via the C2_SERVER_URL environment variable.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 09:35 AM
- analyzed
- Sep 17, 2026, 09:36 AM
Related advisories
- n8n-nodes-sysdiag2@2.0.0
- tailwind-form-kit@0.6.2
- tailwindcss-contact-forms@0.5.8
- @staticj/cropperjs@1.6.0
- tailwind-scrollbar-styles@4.0.3
- tailwindcss-fluid-styles@2.0.7
- bt2-api-gateway-node-js@999.0.0
- tailwindcss-3d-styles@1.2.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.