vite-config-optimizer@1.1.4
Malicious code in vite-config-optimizer (npm)
Analysis
vite-config-optimizer@1.1.4 is a second-stage dropper. Its postinstall hook in loader.js writes a hex-encoded dropper to a temp directory and spawns a detached, unref'd node process (stdio:ignore) that hex-decodes a URL, fetches a second-stage payload from hxxps://jsonkeeper[.]com/b/L435A, parses the response as JSON, writes the session/manifest field to a temp file, and require()s it to execute arbitrary code before cleaning up. The index.js is a decoy claiming to be a Vite plugin while actually implementing a mismatched WebpackCachePlugin, enabling arbitrary post-install code execution from a pastebin-style C2.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 09:50 AM
- analyzed
- Jun 10, 2026, 09:50 AM
Related advisories
- bigops-chat-transfer@35.3.6
- tinkoff-statist-browser-typed-client-coretech.statist.mobile.ci@20.1.2
- twork-products-taiga2-products-timeline@20.6.1
- beaver-ui-actions-button@5.4.7
- fdd41@1.0.0
- axios-native@1.16.3
- @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3
- @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.