LWA-2026-3886 MAL-2026-5727 ↗ confirmed malware

vite-config-optimizer@1.1.4

Malicious code in vite-config-optimizer (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1036.005 · Match Legitimate Resource Name or LocationT1564.001 · Hidden Files and DirectoriesT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

vite-config-optimizer@1.1.4 is a second-stage dropper. Its postinstall hook in loader.js writes a hex-encoded dropper to a temp directory and spawns a detached, unref'd node process (stdio:ignore) that hex-decodes a URL, fetches a second-stage payload from hxxps://jsonkeeper[.]com/b/L435A, parses the response as JSON, writes the session/manifest field to a temp file, and require()s it to execute arbitrary code before cleaning up. The index.js is a decoy claiming to be a Vite plugin while actually implementing a mismatched WebpackCachePlugin, enabling arbitrary post-install code execution from a pastebin-style C2.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 09:50 AM
analyzed
Jun 10, 2026, 09:50 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.