Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageDevSecOps Desk
DevSecOps

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Seven malicious npm packages targeting the Vite ecosystem use blockchain-based C2 to deliver a RAT—an evasion technique that frustrates traditional takedown efforts.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.

The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,

Editorial Analysis

Why it matters

Blockchain C2 channels are effectively untakeable-down, meaning compromised developer environments may maintain persistent attacker access even after initial discovery.

What to do

Scan all JavaScript projects for the named malicious packages and block the identified blockchain RPC endpoints at the network perimeter.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the DevSecOps Desk