vite-plugin-vue-extend@1.0.9
Malicious code in vite-plugin-vue-extend (npm)
Analysis
This package masquerades as a Vite/Vue utility plugin but contains a destructive wiper payload in package/index.min.js. When the exported default function is called, it recursively deletes the dist, bin, and lib directories from the following sibling packages in node_modules: vite, vue, vue-types, typescript, vue-tsc, less, ant-design-vue, store, lib-flexible, dayjs, vue-router, pinia, echarts, axios, and less-loader. The deletions are triggered on staggered timers (every 5-10 minutes at random intervals) with activation dates starting July 2023 (all in the past). Paths use backslash separators, indicating Windows targeting. No network C2 or credential exfiltration — this is a pure data-sabotage payload that destroys a Vue/Vite developer's build toolchain and dependencies.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 08:13 PM
- analyzed
- Jun 15, 2026, 08:16 PM
Related advisories
- vite-plugin-bomb-extend@2.0.0
- vite-plugin-bomb@2.0.0
- super-test-json@1.2.0
- pwdyx@1.0.9
- montreal-core@0.1.0
- tron-toolkit@1.0.1
- cryptostock@1.0.0
- osinthell@1.9.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.