Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @vite-js/ui (npm)

0
High
Published: 07/08/2026 (07/08/2026, 20:37:36 UTC)
Source: GCVE Database
Product: @vite-js/ui

Description

The npm package '@vite-js/ui' is a malicious impersonation of the official 'vite' package. It mimics the legitimate package's metadata and structure but includes a heavily obfuscated payload that executes hidden code. This payload fetches and decodes remote code, executes it via eval, and spawns a detached process that persists beyond the CLI invocation, effectively creating a backdoor. The malicious code is present in versions 7.15.10 and 7.15.16 of '@vite-js/ui'.

Affected software

npmghsa
@vite-js/ui
Affected versions
=7.15.16=7.15.10

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 09:31:46 UTC

Technical Analysis

The '@vite-js/ui' npm package impersonates the official 'vite' package by copying author information, homepage URL, README, and distribution files. It includes an obfuscated Immediately Invoked Function Expression (IIFE) in its CLI bootstrap script that reconstructs strings to hide usage of 'http', 'child_process', 'JSON', 'eval', and 'spawn'. At runtime, it performs a JSON-RPC HTTP fetch, XOR-decodes the response, evaluates the decoded code, and spawns a detached child process running a second fetched payload. This process persists independently of the CLI session, establishing a persistent execution channel. The legitimate 'vite' package does not contain this behavior, indicating this is a dropper and backdoor malware embedded in the package.

Potential Impact

Installing and running the '@vite-js/ui' package versions 7.15.10 or 7.15.16 can lead to execution of arbitrary, obfuscated code fetched from a remote server. This code runs with the privileges of the user invoking the package and establishes a persistent background process, potentially allowing remote attackers to maintain access and execute further malicious actions on the affected system.

Mitigation Recommendations

No official patch or remediation is currently documented for '@vite-js/ui'. Users should avoid installing or running this package, especially versions 7.15.10 and 7.15.16. Verify package authenticity by using the official 'vite' package from trusted sources. Remove any installations of '@vite-js/ui' and investigate systems for the presence of the detached persistent processes spawned by this package. Monitor for unusual child processes and network activity related to this threat. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-7021
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a55ff6168715ace432f1afa

Added to database: 07/14/2026, 09:20:33 UTC

Last enriched: 07/14/2026, 09:31:46 UTC

Last updated: 07/25/2026, 19:53:52 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses