vite-plugin-bomb@2.0.0
Malicious code in vite-plugin-bomb (npm)
Analysis
Package is a trojanized Vite plugin containing a destructive time-bomb. It exports a function that, when the date falls within hardcoded windows, runs `shutdown -s -t 5` to force-shutdown the Windows machine and uses `rimraf` to delete the project's `node_modules` subdirectories for `vue`, `vue-router`, `ant-design-vue`, `lib-flexible`, `less-loader`, `less`, and `vite-plugin-vue-setup-extend`, destroying frontend build infrastructure. No network exfiltration or C2 observed; this is a local wiper/sabotage payload. The package depends on `child_process` (an npm typosquat of Node's built-in module) to gain access to system command execution.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 07:29 PM
- analyzed
- Jun 15, 2026, 07:30 PM
Related advisories
- osinthell@1.9.5
- @offa-uwk/offa-uwk@999.0.6
- vue-plugin-bomb@1.0.1
- vite-plugin-bomb-extend@2.0.0
- super-test-json@1.2.0
- pwdyx@1.0.9
- express-dever@5.1.7
- @web3-helpers/core@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.