ViteVenom: the new npm threat that hides a RAT in import and uses blockchains as C2

Author: Published 4 min de lectura 178 reading

The images in this article were generated with artificial intelligence. How we publish

Security researchers have identified a new wave of malicious packages in the npm ecosystem that target developers using the front Vite construction tool. The campaign, called by some analysts like ViteVenom, is part of a major operation linked to what is known as ChainVeil and shows an important tactical evolution: the direct abuse of the package ecosystem to introduce a loader (loader) that obtains and launches a remote access trojan (RAT) from a command and control infrastructure (C2) based on multiple blockchains.

The technical importance of the attack lies in the method of delivery. Instead of exfiltering the payload from traditional domains or servers that can be closed, the malicious code consults public transactions in chains such as Tron and Binance Smart Chain, decodifies data embedded in transaction fields, and thus recovers points to the next stage of malware. This approach makes public blockchains a kind of distributed and immune storage layer to the authorities' direct take, and makes it difficult to break the attack infrastructure.

ViteVenom: the new npm threat that hides a RAT in import and uses blockchains as C2
Image generated with IA.

The packages detected were published in late June and early July 2026 and were designed to appear to be part of the Vite ecosystem by means of scope names (scoped) emulating the official namespace. Among the identified packages are references to packages with prefixes similar to @ vitecs and variants that include chains such as vite-tree, vite-ui and vite-ts, published under different maintainers and with download figures ranging from tens to more than a thousand. The use of names with scope to pretend to be part of the official project is a tactical change that increases the probability that a developer will unsuspected amount them.

Another alarming feature is that the malicious code is not fired during installation, but at import the unit in time of implementation. This reduces the effectiveness of many security solutions that analyze installation hooks or file signatures in package repositories, because harmful behavior emerges only when the code is part of the bundle or is run in the developer application.

The implications for projects and organizations are clear: the software supply chain is no longer a theoretical vector but an operational field where attackers explore sophisticated techniques to persist and evade interruption. The dependence on public infrastructure, such as blockchains to store points and loads, makes detection and traditional blockade difficult, and requires a rethinking of preventive and incident response controls in development and CI / CD environments.

If you suspect that your project may be affected, immediate actions and best practices include removing any committed package, thoroughly audit the units and configuration files of the shell environment (e.g. .bashrc, .zshrc and .profile) for unauthorized modifications, and rotate credentials that may have been filtered. In the medium term, it is appropriate to strengthen unit governance policies: use verifiable lock files (lockfiles), require revision of units for repositories, apply egress restrictions in CI environments to limit unauthorized outgoing connections, and maintain up-to-date SBOM inventories to know which components are in use. The combination of preventive controls in the development and detection phase of performance time is key.

ViteVenom: the new npm threat that hides a RAT in import and uses blockchains as C2
Image generated with IA.

Software composition analysis tools (SCA) and package scanning can help to detect risk signals, but they need to be complemented by human policies: verify the source of the maintainers, require multifactor authentication for publishing accounts and observe unusual import patterns in the repositories. It is also prudent to incorporate lock rules for outgoing calls to nodes and APIs associated with blockchains used by attackers and monitor DNS and HTTP traffic in search of communications to known C2 servers.

For those who develop with Vite, it is recommended to review official documentation and ecosystem safety practices, and to limit the adoption of packages that do not have a history and verifiable maintenance. You can start by consulting Vite's official website at https: / / vitess.dev / and review good security practices in the supply chain in projects such as OWASP Software Supply Chain: https: / / owasp.org / www-project-software-supply-chain-security /. For those who manage business-scale units, third-party services that offer scanning and continuous monitoring of packages, such as Snyk or package record security tools can be part of a broader mitigation strategy.

Finally, this campaign reinforces a lesson that is already common in safety: there is no single solution. Detection, prevention and response must be integrated with development governance and network controls to mitigate the risk posed by modern supply chains. Those who maintain public projects and package consumers must assume that any new unit requires verification and that the continued visibility of production applications is essential to contain such incidents.

Coverage

Related

More news on the same subject.