LWA-2026-6436 MAL-2026-6984 ↗ confirmed malware

@vite-ln/build-ts@5.17.0

Malicious code in @vite-ln/build-ts (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1204.002 · Malicious File

Analysis

@vite-ln/build-ts is a combosquat of the Vite build tool. The package ships a trojanized bin/vite.js that appends an obfuscated payload after the legitimate Vite bootstrap code. The payload uses a string-shuffling decoder to set up global require/module/__dirname/__filename and executes a decoded function body. The package declares @solana/web3.js, axios, socket[.]io-client, and form-data as devDependencies — none of which are Vite dependencies — indicating a Solana wallet drainer that communicates over HTTP/WebSocket C2 channels. The main bundle (dist/node/chunks/dep-Cy9twKMn.js) also fetches remote content and executes it via new Function, enabling remote code execution. The package claims "Evan You" as author and links to the real Vite repository on GitHub, but is published by a different account under a different scope.

analyzed by
Leitwacht
first seen
Jul 7, 2026, 06:03 PM
analyzed
Jul 7, 2026, 06:05 PM
weekly installs
257

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.