Skip to main content

Malicious code in @uw010010/vite-tree (npm)

0
Critical
Published: 07/13/2026 (07/13/2026, 18:50:08 UTC)
Source: GCVE Database
Product: @uw010010/vite-tree

Description

The npm package @uw010010/vite-tree is a malicious typosquatting package impersonating the legitimate vite package. It contains obfuscated code that executes arbitrary attacker-controlled code on any system where the package's vite binary is run. This includes making network requests to attacker endpoints, decoding and evaluating payloads, and spawning detached background processes for persistence. Systems with this package installed should be considered fully compromised.

Affected software

npmghsa
@uw010010/vite-tree
Affected versions
=3.4.3=3.6.1=3.4.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 19:52:26 UTC

Technical Analysis

The @uw010010/vite-tree package mimics the legitimate vite package by copying metadata and README content. Its bin/vite.js file contains an obfuscated payload that, upon execution, performs HTTP GET and JSON-RPC POST requests to attacker-controlled servers. The response is XOR-decoded and then executed via eval(), and the same payload is launched as a detached background process using child_process.spawn with hidden windows and ignored stdio. This results in arbitrary code execution and persistent backdoor presence on any machine running the package's vite binary.

Potential Impact

Any developer who installs and runs the @uw010010/vite-tree package executes attacker-controlled code with the same privileges as the user. This leads to full system compromise, including potential data theft, credential exposure, and persistent unauthorized access. The presence of detached background processes indicates ongoing control by the attacker even after the initial execution. Secrets and keys stored on the compromised machine are at risk and should be considered exposed.

Mitigation Recommendations

Remove the @uw010010/vite-tree package immediately from all systems. Rotate all secrets, keys, and credentials that were stored or used on the compromised machines from a secure, uncompromised environment. Because the attacker may have established persistent access, assume full compromise and perform thorough incident response and system remediation. There is no official patch or fix for this malicious package; prevention relies on avoiding installation and removing it if found.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10470
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a55ffa768715ace432f96ed

Added to database: 07/14/2026, 09:21:43 UTC

Last enriched: 08/14/2026, 19:52:26 UTC

Last updated: 09/11/2026, 01:25:41 UTC

Views: 67

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses