The images in this article were generated with artificial intelligence. How we publish
Security researchers have identified a new wave of malicious packages in the npm ecosystem that target developers using the front Vite construction tool. The campaign, called by some analysts like ViteVenom, is part of a major operation linked to what is known as ChainVeil and shows an important tactical evolution: the direct abuse of the package ecosystem to introduce a loader (loader) that obtains and launches a remote access trojan (RAT) from a command and control infrastructure (C2) based on multiple blockchains.
The technical importance of the attack lies in the method of delivery. Instead of exfiltering the payload from traditional domains or servers that can be closed, the malicious code consults public transactions in chains such as Tron and Binance Smart Chain, decodifies data embedded in transaction fields, and thus recovers points to the next stage of malware. This approach makes public blockchains a kind of distributed and immune storage layer to the authorities' direct take, and makes it difficult to break the attack infrastructure.

The packages detected were published in late June and early July 2026 and were designed to appear to be part of the Vite ecosystem by means of scope names (scoped) emulating the official namespace. Among the identified packages are references to packages with prefixes similar to @ vitecs and variants that include chains such as vite-tree, vite-ui and vite-ts, published under different maintainers and with download figures ranging from tens to more than a thousand. The use of names with scope to pretend to be part of the official project is a tactical change that increases the probability that a developer will unsuspected amount them.
Another alarming feature is that the malicious code is not fired during installation, but at import the unit in time of implementation. This reduces the effectiveness of many security solutions that analyze installation hooks or file signatures in package repositories, because harmful behavior emerges only when the code is part of the bundle or is run in the developer application.
The implications for projects and organizations are clear: the software supply chain is no longer a theoretical vector but an operational field where attackers explore sophisticated techniques to persist and evade interruption. The dependence on public infrastructure, such as blockchains to store points and loads, makes detection and traditional blockade difficult, and requires a rethinking of preventive and incident response controls in development and CI / CD environments.
If you suspect that your project may be affected, immediate actions and best practices include removing any committed package, thoroughly audit the units and configuration files of the shell environment (e.g. .bashrc, .zshrc and .profile) for unauthorized modifications, and rotate credentials that may have been filtered. In the medium term, it is appropriate to strengthen unit governance policies: use verifiable lock files (lockfiles), require revision of units for repositories, apply egress restrictions in CI environments to limit unauthorized outgoing connections, and maintain up-to-date SBOM inventories to know which components are in use. The combination of preventive controls in the development and detection phase of performance time is key.

Software composition analysis tools (SCA) and package scanning can help to detect risk signals, but they need to be complemented by human policies: verify the source of the maintainers, require multifactor authentication for publishing accounts and observe unusual import patterns in the repositories. It is also prudent to incorporate lock rules for outgoing calls to nodes and APIs associated with blockchains used by attackers and monitor DNS and HTTP traffic in search of communications to known C2 servers.
For those who develop with Vite, it is recommended to review official documentation and ecosystem safety practices, and to limit the adoption of packages that do not have a history and verifiable maintenance. You can start by consulting Vite's official website at https: / / vitess.dev / and review good security practices in the supply chain in projects such as OWASP Software Supply Chain: https: / / owasp.org / www-project-software-supply-chain-security /. For those who manage business-scale units, third-party services that offer scanning and continuous monitoring of packages, such as Snyk or package record security tools can be part of a broader mitigation strategy.
Finally, this campaign reinforces a lesson that is already common in safety: there is no single solution. Detection, prevention and response must be integrated with development governance and network controls to mitigate the risk posed by modern supply chains. Those who maintain public projects and package consumers must assume that any new unit requires verification and that the continued visibility of production applications is essential to contain such incidents.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...