Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.

The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an “unprecedented” four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, According to The Hacker News, cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the vite frontend tooling ecosystem as part of a software supply chain attack.

the malicious package campaign, codenamed vitevenom by checkmarx, marks an expansion of chainveil, which was observed using an “unprecedented” four-tier blockchain-based command-and-control (c2) infrastructure spanning tron,. The development comes amid ongoing regulatory scrutiny in the sector. The Hacker News reports that this marks a significant milestone for the industry. The The Hacker News report provides additional context on the implications for market participants and regulatory frameworks moving forward.