Bottom line: Seven malicious npm packages in the Vite supply chain use a four-tier blockchain C2 infrastructure (Tron) to distribute a remote access trojan.
Security researchers have identified seven compromised npm packages targeting the Vite frontend ecosystem that leverage blockchain-based command-and-control infrastructure. The campaign is classified as an extension of ChainVeil and represents a supply chain compromise.
Checkmarx researchers have documented a campaign involving seven malicious npm packages that infect developers through the Vite frontend toolchain. The packages targeted commonly used build and development dependencies, indicating a coordinated attack on the JavaScript supply chain.
The campaign is called ViteVenom and represents an evolution of previously observed ChainVeil activities. According to the vendor, ChainVeil uses an “unprecedented” four-tier blockchain-based C2 infrastructure spanning Tron. This architecture enables the threat actor to distribute commands and retrieve data while evading traditional network-based detection systems.
For CISOs, this represents elevated risk in validating npm dependencies: blockchain-based C2 channels are harder to block than classical IP-based infrastructure, and supply chain compromise can affect thousands of downstream projects. The Vite targeting indicates organized attacks against the modern web stack.
Source: thehackernews.com · Published July 17, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.