Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    How to Disable Music Videos in Spotify

    July 20, 2026

    Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

    July 20, 2026

    Today’s NYT Connections Hints, Answers for July 20 #1135

    July 20, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
    Cybersecurity

    Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

    InfoForTechBy InfoForTechJuly 19, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Ravie LakshmananJul 17, 2026Software Supply Chain / Malware

    Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.

    The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an “unprecedented” four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan (RAT) capable reverse shell, credential harvesting, file exfiltration, and persistent backdoor injection.

    “This tactic makes disabling or destroying the C2 infrastructure extremely difficult,” Checkmarx researcher Pavan Gudimalla said in an analysis published last month. The activity has been attributed to a threat actor named SuccessKey, with evidence of malicious activity detected as far back as February 27, 2026, when cryptocurrency wallets linked to ViteVenom were activated.

    While the typosquats published to npm in connection with ChainVeil masqueraded as libraries for Tailwind, Sass, ORM, and rate-limiting tools, the latest iteration specifically focuses on developers building applications using the Vite JavaScript and frontend build tool.

    The list of identified packages, published between June 29 and July 3, 2026, is below –

    • @uw010010/vite-tree (1070 Downloads)
    • @vite-tab/tab (289 Downloads)
    • @vite-ln/build-ts (252 Downloads)
    • @vite-mcp/vite-type (239 Downloads)
    • @vite-pro/vite-ui (200 Downloads)
    • @vitets/vite-ts (194 Downloads)
    • @vite-ts/vite-ui (176 Downloads)

    Another crucial difference between the two clusters is that, unlike ChainVeil’s unscoped typosquats (e.g., “rate-limit-flexible”), ViteVenom makes use of scoped package names in an attempt to impersonate the “@vitejs/*” namespace and lend it a veneer of legitimacy.

    The main aspect that unites the two campaigns is the use of shared tier-2 infrastructure, which is used to deliver the RAT. Specifically, this involves the same Tron wallet and Aptos account addresses, which point to the same Binance Smart Chain (BSC) transaction leading to the malware.

    Like in the case of ChainVeil, the malicious code doesn’t execute at install time but at import time, which has the consequence of limiting endpoint security detections. It acts as a loader by reaching out to the blockchain infrastructure to obtain the next-stage –

    • Query the Tron blockchain for the latest transaction from the attacker’s wallet.
    • Decode and reverse the transaction data field to obtain a BSC transaction hash.
    • Query the BSC transaction to extract the encrypted payload from its input field.
    • Decrypt the payload using a hard-coded key.

    “The attacker stores payload pointers as transaction data on public blockchains rather than on domain names that can be seized, making the infrastructure nearly impossible to take down,” Gudimalla explained.

    If the Tron-based payload retrieval method fails, the malware uses Aptos as a backup. The payload, for its part, queries the blockchain to retrieve the C2 configuration and a next-stage loader responsible for launching the RAT. In tandem, there exists a fallback mechanism that fetches the RAT directly from the C2 server over HTTP, completely bypassing the blockchain.

    Users who have installed the packages are advised to remove them immediately, audit dependencies, rotate all credentials, and look for unauthorized modifications to .bashrc, .zshrc, and .profile files.

    “The surface-level differences – different package names, different maintainer accounts, different Tier-1 wallets, different malicious file paths – are consistent with how a single operator would compartmentalize multiple distribution tracks to limit exposure,” Checkmarx said.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

    July 20, 2026

    OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

    July 18, 2026

    How Deception Technology Helps Stop AI Cyberattacks

    July 18, 2026

    New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

    July 18, 2026

    2026 Cybersecurity Forecast: Mid-Year Review & H2 Trends

    July 17, 2026

    E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

    July 17, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202618 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views

    This is the tech that makes Volvo’s latest EV a major step forward

    January 24, 202616 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202618 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202616 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.