chiprook
← Security
SecuritySeptember 27, 2026, 07:54

ChainVeil attack hides malware in vite.config.js via forged merge commit

Researchers detailed a campaign targeting the npm and Vite ecosystem: after one machine is infected, attackers steal Git credentials and force-push obfuscated code into vite.config.js. The payload runs on npm run build, retrieves its C2 address from the Ethereum blockchain (EtherHiding) and executes arbitrary code via eval.

ChainVeil attack hides malware in vite.config.js via forged merge commit
#GitHub#Npm#Vite#Ethereum
Read next
Security

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

Security

GitGuardian: AI-assisted commits leak secrets twice as often

Security

The 27-Day Window: What the BlueMoon Campaign Teaches About Commit-to-Release Gaps

Business

Applied Digital to build $3.2bn Delta Forge 2 AI data center in Alabama