Researchers identified seven malicious npm packages masquerading as Vite-related tooling in a software supply chain campaign dubbed ViteVenom. The packages, linked to the SuccessKey threat actor and described as an expansion of the earlier ChainVeil activity, were published under deceptive Vite-themed namespaces and triggered malicious code at import time through bin/vite.js rather than during installation. The malware used a resilient four-tier blockchain-based command-and-control architecture spanning Tron, Aptos, and Binance Smart Chain, with an HTTP fallback, before delivering a remote access trojan capable of reverse shell access, credential theft, file exfiltration, and persistence.
The campaign primarily put developer workstations at risk, with potential exposure of browser sessions, SSH keys, npm tokens, cloud credentials, API keys, and source code repositories that could enable wider enterprise compromise. Investigators tied ViteVenom to ChainVeil through shared Tier-2 blockchain infrastructure and XOR keys despite changes in package names, maintainer accounts, file paths, and first-stage wallets. Organizations were urged to remove the packages, audit manifests, lockfiles, node_modules, and CI caches, inspect shell startup files and suspicious Node.js activity, review outbound connections to the identified infrastructure, rotate compromised secrets, and rebuild high-risk systems where infection is confirmed.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
A social media post stated that ChainVeil and ViteVenom are part of the North Korea-linked PolinRider campaign, citing a publication by OpenSourceMalware. The post did not provide additional technical details, indicators, or victim information beyond the attribution claim.
Checkmarx Zero identified the ViteVenom campaign and linked it to the earlier ChainVeil npm malware cluster based on shared Tier-2 blockchain infrastructure and XOR keys. The campaign was also attributed to a threat actor tracked as SuccessKey.
The identified malicious packages impersonating Vite-related tooling were published to npm between June 29 and July 3, 2026. The packages executed malicious code at import time and were used to deliver a RAT via blockchain-backed command-and-control infrastructure.
OpenSource Malware published analysis concluding that the ChainVeil and ViteVenom npm supply-chain campaigns are part of the broader DPRK-linked PolinRider operation attributed to Lazarus. The report cited exact overlaps in blockchain C2 infrastructure, including two TRON wallets, one Aptos address, two XOR decryption keys, and shared tradecraft markers.
Checkmarx reported the seven malicious Vite-themed npm packages to npm, and the packages were taken down on July 3, 2026. The report noted that despite the removals, the shared blockchain infrastructure and C2 servers remained online.
On June 16, 2026, Checkmarx Zero reported the ChainVeil npm supply-chain campaign, attributing it to the actor SuccessKey and describing at least nine malicious packages and 14 versions published between May 18 and June 10. Checkmarx said the packages had been reported and removed, but assessed the campaign as ongoing because its blockchain-backed and HTTP fallback C2 infrastructure remained active.
Researchers said evidence of the malicious npm campaign dates back to February 27, 2026. The activity was later tied to the Vite-focused software supply chain operation dubbed ViteVenom.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebsky.app
Open sourcebsky.app
Open sourcetrojan-killer.net
Open sourcethehackernews.com
Open sourceopensourcemalware.com
Open sourcecheckmarx.com
Open sourcecheckmarx.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.