{"id":"MAL-2026-10546","summary":"Malicious code in viteplugiin (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5afbe0fab50b9582867bb208b6cfb20080849e27d27df79711f55e2db69f66bb)\nThe npm package 'viteplugiin' impersonates '@base44/viteplugin' via a one-character insertion (doubled 'i') and ships a hostile payload in dist/index.js, the entry resolved by the package's exports map. After the legitimate-looking plugin code, a large whitespace gap conceals an obfuscated stub that uses Fisher-Yates string shuffles with hardcoded seeds to reconstruct the identifiers 'require', '__dirname', '__filename', 'undefined', and 'constructor', reassigns require/__dirname/__filename onto the global object, obtains the Function constructor, and invokes it on two decoded string bodies — executing attacker-controlled JavaScript at module load time in the consumer's Vite build. Because Vite configs import plugins at config-evaluation time, adding this plugin to vite.config.* causes the payload to run on developer and CI machines during any Vite command. Provenance is consistent with an attack drop: empty author field, no repository/homepage, and package.json 'main' pointing at a nonexistent root index.js while the exports map silently routes '.' to the tampered dist/index.js. The README and internal resolveId targets reference the legitimate '@base44/vite-plugin' as cover.\n","modified":"2026-07-14T04:46:59.041140717Z","published":"2026-07-14T04:13:11Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.28"],"id":"IN-MAL-2026-010390","import_time":"2026-07-14T04:32:00.518400882Z","modified_time":"2026-07-14T04:13:11Z","sha256":"5afbe0fab50b9582867bb208b6cfb20080849e27d27df79711f55e2db69f66bb","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/viteplugiin/v/1.0.28"}],"affected":[{"package":{"name":"viteplugiin","ecosystem":"npm","purl":"pkg:npm/viteplugiin"},"versions":["1.0.28"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"a5117830cc65cc9315c492a29df95283a57a085b8c40fe0433e2162d0f9caaf31bb66c","path":"package.json","sha256":"972a3eafd8c28671cbd02a166fa8bf17cedc6cd31f66ff8e95a04e026f875639"},{"sha256":"f0bbe9b553d38cb1f7d4ab85d7aa49f06bda1e1a1720cbb29001d976e6bfbe79","tlsh":"b7725d6f24f530220f63bc64874f0016b63a8717995dea04774dc3686fa915caab37dc","path":"dist/index.js"}],"package_integrity":[{"filename":"viteplugiin-1.0.28.tgz","hashes":{"sha512_sri":"sha512-ii2ceIIrjlSWEXQ+VmT6IVAgJd22oKswyWNWV+IITYaXT+gZTrU7HBEI1nxpP/fGbTryy7CIrAFbpCOpZ72xag==","sha1":"145c9731d27ed2d3eaf00d1e0aff0504b214627f"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/viteplugiin/MAL-2026-10546.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}