
Seven Malicious npm Packages Target Vite Ecosystem in Supply Chain Attack Using Blockchain-Based C2
CybersecuritySupplyChainAttacksMalwareHackingnpmViteRATBlockchain
Cybersecurity researchers at Checkmarx identified seven malicious npm packages targeting the Vite frontend tooling ecosystem in a software supply chain attack. The campaign, named ViteVenom, expands on ChainVeil’s methodology by employing a four-tier blockchain-based command-and-control (C2) infrastructure utilizing the Tron blockchain. The attack delivers a remote access trojan (RAT) through these compromised packages. No specific dates, CVE IDs, or victim counts were disclosed in the report. The primary impact involves unauthorized access and control over affected systems via the RAT payload.