The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers at Checkmarx have identified seven malicious npm packages, dubbed ViteVenom, that impersonate the @vitejs namespace to target developers using the Vite frontend build tool.
- The campaign is an extension of an earlier attack called ChainVeil and uses a multi-tier command-and-control setup spread across the Tron, Aptos, and Binance Smart Chain blockchains, making the infrastructure nearly impossible to take down.
- Once imported, the malicious code retrieves encrypted payloads from blockchain transactions to deliver a remote access trojan capable of credential harvesting, file exfiltration, and persistent backdoor access.
- The attack has been attributed to a threat actor named SuccessKey and overlaps with a known cluster called PolinRider, assessed to be linked to North Korean hackers.
What to watch next
- Whether npm removes the seven identified packages and any newly discovered related ones
- Further findings from Checkmarx, Socket, or OpenSourceMalware linking the campaign to PolinRider or additional compromised ecosystems
- Guidance for developers who installed the packages, including dependency audits and credential rotation steps
Coverage1
1 report
English national1
All filed from India
Named North Korea · npm · @uw010010/vite-tree · @vite-ln/build-ts · @vite-mcp/vite-type · @vite-pro/vite-ui · @vite-tab/tab · @vitets/vite-ts · @vite-ts/vite-ui · Checkmarx · Jenn Gile · OpenSourceMalware · Pavan Gudimalla
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
