Malicious code in vite-vue-path-map (npm)
The npm package vite-vue-path-map (versions 1.0.0, 1.0.1, and 1.0.2) contains malicious code that activates if a hidden license check fails. This code appends obfuscated JavaScript to the built application, which on page load sends a beacon to an attacker-controlled domain. If the beacon request fails or returns an unexpected response, the code replaces the entire web application with a defacement page in Chinese, controlled remotely by the attacker. This behavior is undocumented and allows remote defacement of any site built with this plugin.
AI Analysis
Technical Summary
The vite-vue-path-map npm package is advertised as a Vite plugin generating a local pathInfo.json map. However, its generateBundle hook appends obfuscated JavaScript to the main JavaScript chunk if a hidden MD5 license check comparing global variables fails. The appended code, stored as base64 constants and decoded at runtime, creates an invisible off-screen image element that sends a beacon request to https://plugin.gin-vue-admin.com/api/shopImage/view?name=logo.svg on every page load. If this request fails or returns a non-image response, an onerror handler executes document.open() and document.write() with a base64-decoded HTML defacement page in Chinese, replacing the developer's application in visitors' browsers. This remote-controlled injection, beaconing, and defacement are not disclosed in the package README and allow whoever controls the attacker's domain to remotely deface any site built with this plugin.
Potential Impact
Sites built using vite-vue-path-map versions 1.0.0, 1.0.1, or 1.0.2 can have malicious JavaScript injected into their production builds. This code sends visitor data to an attacker-controlled domain and can remotely replace the entire web application with a defacement page. This compromises site integrity, availability, and user trust. The attacker has a remote kill-switch to activate or deactivate the malicious behavior at will.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using vite-vue-path-map versions 1.0.0, 1.0.1, and 1.0.2. Remove the package from builds and replace it with a trusted alternative. Audit existing production builds for injected malicious code and redeploy clean builds. Monitor for any unexpected outbound requests to plugin.gin-vue-admin.com and block this domain at network level if possible. Patch status is not yet confirmed — check the vendor advisory or official sources for updates.
Malicious code in vite-vue-path-map (npm)
Description
The npm package vite-vue-path-map (versions 1.0.0, 1.0.1, and 1.0.2) contains malicious code that activates if a hidden license check fails. This code appends obfuscated JavaScript to the built application, which on page load sends a beacon to an attacker-controlled domain. If the beacon request fails or returns an unexpected response, the code replaces the entire web application with a defacement page in Chinese, controlled remotely by the attacker. This behavior is undocumented and allows remote defacement of any site built with this plugin.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vite-vue-path-map npm package is advertised as a Vite plugin generating a local pathInfo.json map. However, its generateBundle hook appends obfuscated JavaScript to the main JavaScript chunk if a hidden MD5 license check comparing global variables fails. The appended code, stored as base64 constants and decoded at runtime, creates an invisible off-screen image element that sends a beacon request to https://plugin.gin-vue-admin.com/api/shopImage/view?name=logo.svg on every page load. If this request fails or returns a non-image response, an onerror handler executes document.open() and document.write() with a base64-decoded HTML defacement page in Chinese, replacing the developer's application in visitors' browsers. This remote-controlled injection, beaconing, and defacement are not disclosed in the package README and allow whoever controls the attacker's domain to remotely deface any site built with this plugin.
Potential Impact
Sites built using vite-vue-path-map versions 1.0.0, 1.0.1, or 1.0.2 can have malicious JavaScript injected into their production builds. This code sends visitor data to an attacker-controlled domain and can remotely replace the entire web application with a defacement page. This compromises site integrity, availability, and user trust. The attacker has a remote kill-switch to activate or deactivate the malicious behavior at will.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately stop using vite-vue-path-map versions 1.0.0, 1.0.1, and 1.0.2. Remove the package from builds and replace it with a trusted alternative. Audit existing production builds for injected malicious code and redeploy clean builds. Monitor for any unexpected outbound requests to plugin.gin-vue-admin.com and block this domain at network level if possible. Patch status is not yet confirmed — check the vendor advisory or official sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13465
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7573b5bf8831d539d93b77
Added to database: 08/07/2026, 05:57:09 UTC
Last enriched: 08/07/2026, 07:42:29 UTC
Last updated: 08/07/2026, 07:42:29 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.