New ViteVenom Malware Targets Developers with Blockchain C2 RAT

New ViteVenom Malware Targets Developers with Blockchain C2 RAT

First seen 20 Jul 2026, 17:39 UTC ThehackernewsScworld 76% similarity 69.0

Article Content

Browse articles
ThreatCluster

Checkmarx researchers have identified a cluster of seven malicious npm packages named ViteVenom, targeting the Vite frontend ecosystem. The campaign, attributed to the threat actor SuccessKey, builds on tactics from the ChainVeil attack. ViteVenom uses a blockchain-based command-and-control (C2) infrastructure across Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan (RAT). This RAT can execute a reverse shell, harvest credentials, exfiltrate files, and inject persistent backdoors. The malware employs scoped package names to impersonate legitimate Vite packages, executing malicious code at import time to evade detection. Users are advised to remove affected packages, audit dependencies, and rotate credentials. The attack highlights the ongoing threat of software supply chain vulnerabilities.

Key Points: • ViteVenom targets the Vite frontend ecosystem with seven malicious npm packages. • The malware uses blockchain technology for its command-and-control infrastructure. • Developers are urged to remove affected packages and secure their systems immediately.

ThreatCluster AI

Timeline

2026-07-17
ViteVenom malware cluster discovered
Checkmarx researchers reported the identification of seven malicious npm packages targeting Vite developers.
Thehackernews
2026-07-20
Scworld reports on ViteVenom campaign
Scworld published details on the ViteVenom malware cluster and its sophisticated attack methods.
Scworld

Community

Browse all →