@vite-tab/tabui@7.15.16
Malicious code in @vite-tab/tabui (npm)
Analysis
@vite-tab/tabui@7.15.16 is a combosquat of the Vite build tool that ships a trojanized clone of the real Vite source code with an injected obfuscated JavaScript payload in bin/vite.js. The package claims to be Vite (author "Evan You", repository github[.]com/vitejs/vite) but includes @solana/web3.js, axios, socket[.]io-client, and form-data as devDependencies — the standard dependency set for Solana wallet drainers. The bin/vite.js entry point appends a heavily obfuscated self-executing payload after the legitimate Vite bootstrap code, using a custom string-shuffling decoder to capture require() and execute the drainer logic.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 06:46 AM
- analyzed
- Jul 14, 2026, 06:47 AM
Related advisories
- @vite-tab/tab@5.7.0
- node-fsagent@3.69.0
- react-hot-svg@1.1.5
- theta-sdk-js@1.2.14
- polymarket-mcp-v2@2.1.6
- tslint-conf@7.2.1
- viteplugiin@1.0.28
- express-guardian@1.4.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.