⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

July 17, 2026

Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The campaign, codenamed ViteVenom, is an expansion of the previously observed ChainVeil operation and uses an unprecedented four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan (RAT) capable of reverse shell, credential harvesting, file exfiltration, and persistent backdoor injection.

The activity has been attributed to a threat actor named SuccessKey, with evidence of malicious activity dating back to February 27, 2026. The packages, published between June 29 and July 3, 2026, include @uw010010/vite-tree, @vite-tab/tab, @vite-ln/build-ts, @vite-mcp/vite-type, @vite-pro/vite-ui, @vitets/vite-ts, and @vite-ts/vite-ui. Unlike ChainVeil’s unscoped typosquats, ViteVenom uses scoped package names to impersonate the @vitejs/* namespace.

The malicious code executes at import time, not install time, limiting endpoint security detections. It acts as a loader by querying the Tron blockchain for the latest transaction from the attacker’s wallet, decoding and reversing the transaction data to obtain a Binance Smart Chain transaction hash, then extracting and decrypting the payload. If the Tron method fails, Aptos serves as a backup. The payload retrieves C2 configuration and a next-stage loader for the RAT, with a fallback mechanism fetching the RAT directly over HTTP.

Users who have installed these packages are advised to remove them immediately, audit dependencies, rotate all credentials, and check for unauthorized modifications to .bashrc, .zshrc, and .profile files.

Attack groups: SuccessKey

Malware: ViteVenom, ChainVeil

Companies: Checkmarx

Products: Vite, npm