Skip to main content

Malicious code in vite-plugin-bug-tracker (npm)

0
High
Published: 08/25/2026 (08/25/2026, 08:10:02 UTC)
Source: GCVE Database
Product: vite-plugin-bug-tracker

Description

The npm package vite-plugin-bug-tracker (versions 1.0.0 and 1.1.0) contains malicious code that injects an inline script into every built HTML page. This script harvests personally identifiable information (PII) such as account usernames, phone numbers, and real names from sessionStorage in the end user's browser. The stolen data is exfiltrated to a concealed remote endpoint using obfuscated URLs decoded and decoded at runtime. The plugin also intercepts sessionStorage writes to trigger immediate data exfiltration, resulting in production applications unknowingly shipping a PII harvester.

Affected software

npmghsa
vite-plugin-bug-tracker
Affected versions
=1.0.0=1.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 18:48:32 UTC

Technical Analysis

The vite-plugin-bug-tracker npm package versions 1.0.0 and 1.1.0 include a malicious transformIndexHtml hook that injects an inline script into all built HTML pages. This script reads sensitive user data from sessionStorage fields like account/username, phone number, and real name. It exfiltrates this data via fetch (no-cors), sendBeacon, or Image requests to a runtime-decoded and XOR-obfuscated URL, preventing easy detection by static or network inspection. Additionally, the plugin monkey-patches sessionStorage.setItem to trigger data exfiltration whenever matching keys are written. This behavior effectively turns any application built with this plugin into a PII harvesting tool without developer or user awareness.

Potential Impact

Applications built using vite-plugin-bug-tracker versions 1.0.0 and 1.1.0 expose end users to privacy violations by leaking personally identifiable information stored in sessionStorage. The exfiltration is stealthy due to runtime URL obfuscation and multiple transmission methods, making detection difficult. This compromises user privacy and may violate data protection regulations depending on jurisdiction.

Mitigation Recommendations

No official patch or remediation guidance is provided in the source data. Users and developers should immediately remove vite-plugin-bug-tracker versions 1.0.0 and 1.1.0 from their projects and avoid using this package. Review and audit dependencies for malicious code before inclusion. Monitor for updates or advisories from the package maintainers or security communities for any official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-14479
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a8d9ae7acd9273b493e1749

Added to database: 08/25/2026, 13:38:47 UTC

Last enriched: 09/10/2026, 18:48:32 UTC

Last updated: 10/02/2026, 14:22:08 UTC

Views: 29

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses