LWA-2026-6743 confirmed malware

@vite-tab/tabui@7.15.16

Malicious code in @vite-tab/tabui (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information

Analysis

@vite-tab/tabui@7.15.16 is a combosquat of the Vite build tool that ships a trojanized clone of the real Vite source code with an injected obfuscated JavaScript payload in bin/vite.js. The package claims to be Vite (author "Evan You", repository github[.]com/vitejs/vite) but includes @solana/web3.js, axios, socket[.]io-client, and form-data as devDependencies — the standard dependency set for Solana wallet drainers. The bin/vite.js entry point appends a heavily obfuscated self-executing payload after the legitimate Vite bootstrap code, using a custom string-shuffling decoder to capture require() and execute the drainer logic.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 06:46 AM
analyzed
Jul 14, 2026, 06:47 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.