@vite-tab/tab@5.7.0
Malicious code in @vite-tab/tab (npm)
Analysis
@vite-tab/tab is a trojanized clone of the Vite build tool. The package claims the same author (Evan You), description, and repository URL as the real Vite, but ships an obfuscated payload appended to bin/vite.js that uses a custom string-shuffling algorithm to decode and execute a second-stage script. The devDependencies include @solana/web3.js, axios, socket[.]io-client, and form-data — a dependency stack associated with crypto-wallet credential theft. The same file also fetches remote content and executes it via the Function constructor, enabling a remote-code-execution dropper. When the package is installed and the vite binary is run, the obfuscated payload executes and can download and run arbitrary code from a remote server.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 05:55 PM
- analyzed
- Jul 7, 2026, 05:58 PM
- weekly installs
- 311
Related advisories
- @vite-tab/tabui@7.15.16
- @bobfrankston/msger@0.1.388
- react-icons-svgo@1.5.4
- npm-rce-poc@1.0.13
- @withoneltd/lucky@0.1.4
- @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3
- mailconfirmer@3.3.11
- codyx-ai-linux-x64-musl@1.14.42
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.