LWA-2026-6434 MAL-2026-6988 ↗ confirmed malware

@vite-tab/tab@5.7.0

Malicious code in @vite-tab/tab (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1204.002 · Malicious File

Analysis

@vite-tab/tab is a trojanized clone of the Vite build tool. The package claims the same author (Evan You), description, and repository URL as the real Vite, but ships an obfuscated payload appended to bin/vite.js that uses a custom string-shuffling algorithm to decode and execute a second-stage script. The devDependencies include @solana/web3.js, axios, socket[.]io-client, and form-data — a dependency stack associated with crypto-wallet credential theft. The same file also fetches remote content and executes it via the Function constructor, enabling a remote-code-execution dropper. When the package is installed and the vite binary is run, the obfuscated payload executes and can download and run arbitrary code from a remote server.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 05:55 PM
analyzed
Jul 7, 2026, 05:58 PM
weekly installs
311

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.