vitest-cli@1.0.0
Malicious code in vitest-cli (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
vitest-cli@1.0.0 is a combosquat on the legitimate vitest testing framework. Its postinstall hook activates an obfuscated downloader in lib/postinstall/index.js that fetches a remote payload from hxxps://jsonkeeper[.]com/b/W33XO and executes it via new Function(), giving the attacker arbitrary code execution on the installer's system. The payload retries up to 3 times with 10-minute intervals. No credentials or environment variables are exfiltrated — the attack vector is remote second-stage payload execution.
- analyzed by
- Leitwacht
- first seen
- Jun 19, 2026, 01:22 PM
- analyzed
- Jun 19, 2026, 01:23 PM
Related advisories
- react-check-error@2.1.6
- chai-as-uphelded@6.11.4
- chai-as-forgeted@9.24.6
- ts-escro@0.0.6
- panrouter@5.0.0
- panrouter-admin@5.0.0
- chai-as-attested@6.0.3
- assert-kit@4.3.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.