@vite-js/vui@7.14.16
Malicious code in @vite-js/vui (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting Interpreter
Analysis
Combosquat of the Vite build tool: the package name @vite-js/vui mimics the real @vitejs/vite, claims author "Evan You", and points to the real Vite repository. The devDependencies include @solana/web3.js, axios, socket[.]io-client, and form-data — the dependency stack commonly used by Solana wallet drainers. The same publisher also published @vite-js/ui with remote code execution capabilities. The package has no repository, no verifiable source, and its dependencies are inconsistent with a build tool.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 07:06 AM
- analyzed
- Jul 14, 2026, 07:07 AM
Related advisories
- awesome-terminal@1.0.3
- type-context@3.2.7
- terminal-mascot@3.5.2
- pure-folder-three@0.7.3
- tinyparrot@0.4.1
- react-hot-svg@1.1.5
- notify-utilities@1.3.5
- client-cookies-agent@99.9.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.