Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack The malicious package campaign codenamed ViteVenom by Checkmarx marks an expansion of ChainVeil which was observed using an unprecedented fourtier blockchainbased commandandcontrol C2 infrastructure spanning Tron