Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT 12%

By Ravie Lakshmanan12%

7/17/2026, 11:54:51 AM

BS Summary: This article contains 15 faulty reasoning types, including Ambiguity (Equivocation), Biased Writer Voice, and Appeal to Authority, with Confirmation Bias as the most egregious example at 24.9% saturation with 133 hits. Analysis detected 877 faulty-reasoning hits from 535 analyzed words, generating a BS Score of 29% and a BS Rank of 12% (19,276 of 21,887 articles). This article is better (less manipulative) than 88.10% of the article peer group.

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. 
The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan (RAT) capable reverse shell, credential harvesting, file exfiltration, and persistent backdoor injection. 
"This tactic makes disabling or destroying the C2 infrastructure extremely difficult," Checkmarx researcher Pavan Gudimalla said in an analysis published last month. 
The activity has been attributed to a threat actor named SuccessKey, with evidence of malicious activity detected as far back as February 27, 2026, when cryptocurrency wallets linked to ViteVenom were activated. 
While the typosquats published to npm in connection with ChainVeil masqueraded as libraries for Tailwind, Sass, ORM, and rate-limiting tools, the latest iteration specifically focuses on developers building applications using the Vite JavaScript and frontend build tool. 
The list of identified packages, published between June 29 and July 3, 2026, is below - 
* @uw010010/vite-tree (1070 Downloads) 
* @vite-tab/tab (289 Downloads) 
* @vite-ln/build-ts (252 Downloads) 
* @vite-mcp/vite-type (239 Downloads) 
* @vite-pro/vite-ui (200 Downloads) 
* @vitets/vite-ts (194 Downloads) 
* @vite-ts/vite-ui (176 Downloads) 
Another crucial difference between the two clusters is that, unlike ChainVeil's unscoped typosquats (e.g., "rate-limit-flexible"), ViteVenom makes use of scoped package names in an attempt to impersonate the "@vitejs/*" namespace and lend it a veneer of legitimacy. 
The main aspect that unites the two campaigns is the use of shared tier-2 infrastructure, which is used to deliver the RAT. 
Specifically, this involves the same Tron wallet and Aptos account addresses, which point to the same Binance Smart Chain (BSC) transaction leading to the malware. 
Like in the case of ChainVeil, the malicious code doesn't execute at install time but at import time, which has the consequence of limiting endpoint security detections. 
It acts as a loader by reaching out to the blockchain infrastructure to obtain the next-stage - 
* Query the Tron blockchain for the latest transaction from the attacker's wallet. 
* Decode and reverse the transaction data field to obtain a BSC transaction hash. 
* Query the BSC transaction to extract the encrypted payload from its input field. 
* Decrypt the payload using a hard-coded key. 
"The attacker stores payload pointers as transaction data on public blockchains rather than on domain names that can be seized, making the infrastructure nearly impossible to take down," Gudimalla explained. 
The payload, for its part, queries the blockchain to retrieve the C2 configuration and a next-stage loader responsible for launching the RAT. 
In tandem, there exists a fallback mechanism that fetches the RAT directly from the C2 server over HTTP, completely bypassing the blockchain. 
Users who have installed the packages are advised to remove them immediately, audit dependencies, rotate all credentials, and look for unauthorized modifications to .bashrc, .zshrc, and .profile files. 
"The surface-level differences - different package names, different maintainer accounts, different Tier-1 wallets, different malicious file paths - are consistent with how a single operator would compartmentalize multiple distribution tracks to limit exposure," Checkmarx said. 
Article reasoning-pattern comparisonThis article: 24.9%Ravie Lakshmanan: 1.5%The Hacker News: 1.9%Confirmation Bias24.9%This article: 6.0%Ravie Lakshmanan: 1.4%The Hacker News: 1.2%Anchoring Bias6.0%This article: 0.0%Ravie Lakshmanan: 2.4%The Hacker News: 3.3%Availability Heuristic0.0%This article: 13.5%Ravie Lakshmanan: 1.7%The Hacker News: 1.5%Representativeness Heuristic13.5%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Hindsight Bias0.0%This article: 13.3%Ravie Lakshmanan: 2.4%The Hacker News: 2.5%Overconfidence Bias13.3%This article: 2.2%Ravie Lakshmanan: 2.4%The Hacker News: 2.7%Framing Effect2.2%This article: 5.2%Ravie Lakshmanan: 0.8%The Hacker News: 1.0%Loss Aversion5.2%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Status Quo Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 0.0%Ravie Lakshmanan: 1.1%The Hacker News: 1.3%Optimism Bias0.0%This article: 9.7%Ravie Lakshmanan: 1.5%The Hacker News: 1.6%Pessimism Bias9.7%This article: 12.0%Ravie Lakshmanan: 7.7%The Hacker News: 6.7%Negativity Bias12.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.6%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.2%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 4.1%Ravie Lakshmanan: 2.4%The Hacker News: 1.5%Recency Bias4.1%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 15.7%Ravie Lakshmanan: 4.9%The Hacker News: 4.0%Appeal to Authority15.7%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 1.6%False Dilemma0.0%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Circular Reasoning0.0%This article: 4.1%Ravie Lakshmanan: 4.0%The Hacker News: 4.3%Hasty Generalization4.1%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Bandwagon0.0%This article: 0.0%Ravie Lakshmanan: 1.1%The Hacker News: 1.1%Appeal to Emotion0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Begging the Question0.0%This article: 10.7%Ravie Lakshmanan: 2.1%The Hacker News: 1.9%Post Hoc (False Cause)10.7%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 19.1%Ravie Lakshmanan: 3.8%The Hacker News: 2.3%Ambiguity (Equivocation)19.1%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 3.4%The Hacker News: 1.4%Unattributed Quote0.0%This article: 0.0%Ravie Lakshmanan: 2.6%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 18.3%Ravie Lakshmanan: 2.5%The Hacker News: 2.3%Biased Writer Voice18.3%This article: 5.2%Ravie Lakshmanan: 2.4%The Hacker News: 4.4%Indoctrination5.2%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

535 words analyzed.

Speakers

3speakers16%attributed speech448writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 12 words • 100.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 49 words • 100.0% coveragePavan Gudimalla • 22 words • 0.0% coverageWriter's voice • 32 words • 0.0% coverageWriter's voice • 37 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 37 words • 100.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageGudimalla • 30 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 28 words • 100.0% coverageCheckmarx • 35 words • 0.0% coverage
Selected voice

Checkmarx

100%flagged-word coverage
35 attributed words40% of attributed speech57% writer coverage
0%12.5%25.0%Biased Writer Voice-21.9 ptsWriter: 21.9%Checkmarx: 0.0%0.0%Indoctrination-6.3 ptsWriter: 6.3%Checkmarx: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.