basic-vite@1.0.0
Malicious code in basic-vite (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1087.001 · Local AccountT1012 · Query RegistryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols
Analysis
basic-vite@1.0.0 runs a preinstall script that collects the installer's hostname, home directory, username, DNS server list, /etc/passwd, and /etc/hosts, then exfiltrates the data via HTTPS POST to md3wko7hlcmvfsq16xh2higublhc53ts[.]oastify[.]com (a Burp Collaborator intercept domain). The package has no repository, no description, and its sole purpose is system reconnaissance and data exfiltration on install.
- analyzed by
- Leitwacht
- first seen
- Jul 25, 2026, 07:22 PM
- analyzed
- Jul 25, 2026, 07:22 PM
Related advisories
- env-config-f281@1.0.0
- stellarfixer@1.0.0
- simplisafe-gatsby@1.0.1
- array-sort-helper@1.0.0
- text-line-parser@1.0.0
- date-sanitize-helper@1.0.0
- page-navigation@1.0.1
- xo-member-components@28.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.