vite-pwa-config@1.1.1
Malicious code in vite-pwa-config (npm)
Analysis
Combosquat package impersonating the legitimate vite-plugin-pwa library. On import, the package spawns a detached Node.js child process that fetches a remote payload from jsonkeeper[.]com (hxxps://www[.]jsonkeeper[.]com/b/FNOBS) via axios, then executes the fetched code using the Function constructor with access to require, enabling arbitrary remote code execution. The payload is fetched with a custom header (x-secret-key) and retries up to 5 times on failure. The package has no lifecycle hooks — the malicious code runs on import via the detached subprocess in dist/index.mjs.
- analyzed by
- Leitwacht
- first seen
- Jul 9, 2026, 10:09 AM
- analyzed
- Jul 9, 2026, 10:11 AM
Related advisories
- chai-as-disarmed@3.2.3
- zredis-typed@1.0.127
- zod-pino434@1.0.127
- polygon-gamma-apis@1.5.2
- execfences@5.0.2
- compose-logger-stand@1.0.126
- chalk-plus-ts@1.0.4
- assertcoreutils@2.3.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.