#ViteVenom
Incident/Operation
2026-07-14 • Sequel to ChainVeil npm malware: ViteVenom
ViteVenom is a June–July 2026 cluster of seven malicious npm packages that impersonated trusted namespaces in the Vite and Vitest developer ecosystems. The packages used a blockchain-based, multi-tier command-resolution design and delivered a remote-access Trojan, sharing backend addresses, decryption keys, and payloads with ChainVeil. Researchers assessed with high confidence that both tracks shared an operator or backend and linked them to PolinRider, a North Korean Lazarus Group campaign, while noting that an infrastructure-service arrangement could not be completely excluded.
-
2
Tagged Reports
-
2
Unique Authors
-
4
Active Days