Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Seven malicious npm packages targeting the Vite ecosystem use blockchain-based C2 to deliver a RAT—an evasion technique that frustrates traditional takedown efforts.
Summary written by editorial AI · Source link below
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.
The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,
Editorial Analysis
Blockchain C2 channels are effectively untakeable-down, meaning compromised developer environments may maintain persistent attacker access even after initial discovery.
Scan all JavaScript projects for the named malicious packages and block the identified blockchain RPC endpoints at the network perimeter.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the DevSecOps Desk
- CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages20 Jul
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts19 Jul
- VulnHunter: Capital One's agentic AI code security tool17 Jul
- The Prover Is the Judge: Verified Security Software from AI Coding Agents in Ada/SPARK17 Jul
- PatchIsland: Orchestration of LLM Agents for Continuous Vulnerability Repair17 Jul