4w ago · hacker-news
A software supply chain attack dubbed ViteVenom has targeted the Vite JavaScript ecosystem through seven malicious npm packages. The campaign, attributed to threat actor SuccessKey, uses a multi-tier blockchain-based command-and-control (C2) infrastructure across Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan (RAT). The malware executes at import time to evade detection and retrieves payloads via blockchain transactions, making takedown efforts extremely difficult. Fallback mechanisms include direct HTTP retrieval from a C2 server.