LWA-2026-6746 MAL-2026-10619 ↗ confirmed malware

@vite-js/vui@7.14.16

Malicious code in @vite-js/vui (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting Interpreter

Analysis

Combosquat of the Vite build tool: the package name @vite-js/vui mimics the real @vitejs/vite, claims author "Evan You", and points to the real Vite repository. The devDependencies include @solana/web3.js, axios, socket[.]io-client, and form-data — the dependency stack commonly used by Solana wallet drainers. The same publisher also published @vite-js/ui with remote code execution capabilities. The package has no repository, no verifiable source, and its dependencies are inconsistent with a build tool.

analyzed by
Leitwacht
first seen
Jul 14, 2026, 07:06 AM
analyzed
Jul 14, 2026, 07:07 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.