LWA-2026-5420 confirmed malware

vite-plugin-bomb@2.0.0

Malicious code in vite-plugin-bomb (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1485 · Data DestructionT1529 · System Shutdown/Reboot

Analysis

Package is a trojanized Vite plugin containing a destructive time-bomb. It exports a function that, when the date falls within hardcoded windows, runs `shutdown -s -t 5` to force-shutdown the Windows machine and uses `rimraf` to delete the project's `node_modules` subdirectories for `vue`, `vue-router`, `ant-design-vue`, `lib-flexible`, `less-loader`, `less`, and `vite-plugin-vue-setup-extend`, destroying frontend build infrastructure. No network exfiltration or C2 observed; this is a local wiper/sabotage payload. The package depends on `child_process` (an npm typosquat of Node's built-in module) to gain access to system command execution.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 07:29 PM
analyzed
Jun 15, 2026, 07:30 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.