Scworld
New ViteVenom Malware Targets Developers with Blockchain C2 RAT
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Checkmarx researchers have identified a cluster of seven malicious npm packages named ViteVenom, targeting the Vite frontend ecosystem. The campaign, attributed to the threat actor SuccessKey, builds on tactics from the ChainVeil attack. ViteVenom uses a blockchain-based command-and-control (C2) infrastructure across Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan (RAT). This RAT can execute a reverse shell, harvest credentials, exfiltrate files, and inject persistent backdoors. The malware employs scoped package names to impersonate legitimate Vite packages, executing malicious code at import time to evade detection. Users are advised to remove affected packages, audit dependencies, and rotate credentials. The attack highlights the ongoing threat of software supply chain vulnerabilities.
Key Points: • ViteVenom targets the Vite frontend ecosystem with seven malicious npm packages. • The malware uses blockchain technology for its command-and-control infrastructure. • Developers are urged to remove affected packages and secure their systems immediately.