LWA-2026-7131 MAL-2026-11131 ↗ confirmed malware

basic-vite@1.0.0

Malicious code in basic-vite (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1087.001 · Local AccountT1012 · Query RegistryT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

basic-vite@1.0.0 runs a preinstall script that collects the installer's hostname, home directory, username, DNS server list, /etc/passwd, and /etc/hosts, then exfiltrates the data via HTTPS POST to md3wko7hlcmvfsq16xh2higublhc53ts[.]oastify[.]com (a Burp Collaborator intercept domain). The package has no repository, no description, and its sole purpose is system reconnaissance and data exfiltration on install.

analyzed by
Leitwacht
first seen
Jul 25, 2026, 07:22 PM
analyzed
Jul 25, 2026, 07:22 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.