Supply chain New npm malware cluster targets Vite ecosystem July 20, 2026 Share By SC Staff (Credit: Araki Illustrations – stock.adobe.com) As outlined in The Hacker News, Checkmarx cybersecurity researchers have uncovered a new cluster of seven malicious npm packages, dubbed ViteVenom, that are specifically targeting developers using the Vite frontend tooling ecosystem. This represents an expansion of previous software supply chain attacks. The ViteVenom campaign, attributed to the threat actor SuccessKey, builds upon the tactics seen in the earlier ChainVeil attack. It utilizes a sophisticated, multi-tier blockchain-based command-and-control infrastructure across Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan (RAT). This RAT is capable of executing a reverse shell, harvesting credentials, exfiltrating files, and injecting persistent backdoors. Unlike previous attacks, ViteVenom employs scoped package names to impersonate the "@vitejs/*" namespace, aiming for increased legitimacy. The malware's malicious code executes at import time, not install time, to evade endpoint security detections. It queries blockchains to retrieve encrypted payloads, making the C2 infrastructure extremely difficult to dismantle. Users who may have installed these packages are strongly advised to remove them immediately, audit their dependencies, rotate all credentials, and check for unauthorized system modifications. Source: The Hacker News SC Staff Related Supply chain Jscrambler npm package version 8.14.0 contained a malicious infostealer SC Staff July 13, 2026 The jscrambler supply chain attack involved a malicious preinstall hook within version 8.14.0 of the npm package. Supply chain OpenMandriva Linux project reportedly targeted in attempted sabotage after contributor dispute SC Staff July 10, 2026 The incident occurred after a contributor's abusive behavior reportedly led to some members leaving the project. Supply chain Injective Labs SDK npm package compromised to steal cryptocurrency keys SC Staff July 10, 2026 The supply-chain attack was detected by application security companies Socket, Ox Security, and StepSecurity via version 1.20.21 of the @injectivelabs/sdk-ts npm package, which has 50,000 weekly downloads. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds