vite-config-svg@1.1.7
Malicious code in vite-config-svg (npm)
Analysis
vite-config-svg is a combosquat of the Vite build-tool ecosystem. Its exported getPlugin() and setPlugin() functions, documented as SVG file validators, instead spawn a child process that runs "npm install rollup-plugin-polyfill-helper --no-save --silent --no-audit --no-fund" and then require() the installed package. The command and package name are base64-encoded in the source to hide the payload. rollup-plugin-polyfill-helper is a known-malicious package published by the same account. Any consumer calling the exported API will silently install and load this malware.
- analyzed by
- Leitwacht
- first seen
- Jul 22, 2026, 06:27 AM
- analyzed
- Jul 22, 2026, 06:28 AM
Related advisories
- json-validator-utils@1.0.1
- ai-pro-sdk@2.0.3
- crypto-validate-lib@1.0.0
- layer2-sdk@1.0.1
- arb-kit@1.0.1
- @vite-tab/tabui@7.15.16
- node-fsagent@3.69.0
- react-hot-svg@1.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.