LWA-2026-5429 confirmed malware

vite-plugin-vue-extend@1.0.9

Malicious code in vite-plugin-vue-extend (npm)

T1485 · Data DestructionT1059.007 · JavaScriptT1070.004 · File Deletion

Analysis

This package masquerades as a Vite/Vue utility plugin but contains a destructive wiper payload in package/index.min.js. When the exported default function is called, it recursively deletes the dist, bin, and lib directories from the following sibling packages in node_modules: vite, vue, vue-types, typescript, vue-tsc, less, ant-design-vue, store, lib-flexible, dayjs, vue-router, pinia, echarts, axios, and less-loader. The deletions are triggered on staggered timers (every 5-10 minutes at random intervals) with activation dates starting July 2023 (all in the past). Paths use backslash separators, indicating Windows targeting. No network C2 or credential exfiltration — this is a pure data-sabotage payload that destroys a Vue/Vite developer's build toolchain and dependencies.

analyzed by
Leitwacht
first seen
Jun 15, 2026, 08:13 PM
analyzed
Jun 15, 2026, 08:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.