@vite-ln/build-ts@5.17.0
Malicious code in @vite-ln/build-ts (npm)
Analysis
@vite-ln/build-ts is a combosquat of the Vite build tool. The package ships a trojanized bin/vite.js that appends an obfuscated payload after the legitimate Vite bootstrap code. The payload uses a string-shuffling decoder to set up global require/module/__dirname/__filename and executes a decoded function body. The package declares @solana/web3.js, axios, socket[.]io-client, and form-data as devDependencies — none of which are Vite dependencies — indicating a Solana wallet drainer that communicates over HTTP/WebSocket C2 channels. The main bundle (dist/node/chunks/dep-Cy9twKMn.js) also fetches remote content and executes it via new Function, enabling remote code execution. The package claims "Evan You" as author and links to the real Vite repository on GitHub, but is published by a different account under a different scope.
- analyzed by
- Leitwacht
- first seen
- Jul 7, 2026, 06:03 PM
- analyzed
- Jul 7, 2026, 06:05 PM
- weekly installs
- 257
Related advisories
- @vite-tab/tab@5.7.0
- @bobfrankston/msger@0.1.388
- react-icons-svgo@1.5.4
- npm-rce-poc@1.0.13
- @withoneltd/lucky@0.1.4
- @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3
- mailconfirmer@3.3.11
- codyx-ai-linux-x64-musl@1.14.42
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.