vue-plugin-bomb@1.0.1
Malicious code in vue-plugin-bomb (npm)
Analysis
vue-plugin-bomb@1.0.1 is a destructive wiper. Its index.js imports the npm package 'child_process' (typosquatting the Node.js core module) and uses process.execSync on a timed schedule. During specific date windows (June through September 2023), the code repeatedly executes 'shutdown -s -t 5' to force a system shutdown with 5-second delay. Additionally, on a broader schedule it recursively deletes the following directories and files from the project's node_modules: vue/dist, vue-router/dist, vue-router/index.js, vant/lib, vant/es (Jul-Aug); and pinia/dist, pinia/index.js, vite-plugin-vue-setup-extend/dist, axios/dist, axios/index.js, vite/dist, vite/bin, vite/types, vite/index.js (Sep onward). The package has no legitimate functionality — it is solely a time-bomb wiper targeting Vue/Vite/Axios-based Node.js projects, with no exfiltration or C2.
- analyzed by
- Leitwacht
- first seen
- Jun 15, 2026, 10:43 PM
- analyzed
- Jun 15, 2026, 10:44 PM
Related advisories
- vite-plugin-bomb-extend@2.0.0
- vite-plugin-bomb@2.0.0
- osinthell@1.9.5
- @offa-uwk/offa-uwk@999.0.6
- vourfly-tele@4.7.6
- vite-plugin-vue-extend@1.0.9
- super-test-json@1.2.0
- pwdyx@1.0.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.