{"id":"MAL-2026-11131","summary":"Malicious code in basic-vite (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ab736217e52ecd2e4aa966da6192e434d69f7d34cc5b7a1ce72c6c6ece6aff56)\npackage.json declares `preinstall: node index.js`, so `npm install basic-vite` auto-executes index.js. The script collects host identity data (hostname, username, home directory, DNS servers, current working directory, package.json contents) and reads /etc/passwd and /etc/hosts, then POSTs the collected payload over HTTPS to the hardcoded Burp Collaborator subdomain md3wko7hlcmvfsq16xh2higublhc53ts.oastify.com. The package name suggests a Vite-related utility, but no such functionality is present; the sole behavior is install-time data exfiltration to an attacker-controlled out-of-band interaction host.\n","modified":"2026-07-28T14:37:23.930221744Z","published":"2026-07-28T13:32:35Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-010892","import_time":"2026-07-28T14:19:57.783881224Z","modified_time":"2026-07-28T13:32:35Z","sha256":"ab736217e52ecd2e4aa966da6192e434d69f7d34cc5b7a1ce72c6c6ece6aff56","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/basic-vite/v/1.0.0"}],"affected":[{"package":{"name":"basic-vite","ecosystem":"npm","purl":"pkg:npm/basic-vite"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"index.js","sha256":"f79d79cd9a32220f4d47700c28a4347b9befaf7e567a44a5a722a4c8f0fdb745","tlsh":"19411199a2c917330de210c06a0c70812359fa777169e8d077cf42969f869f8bb326f3"}],"package_integrity":[{"filename":"basic-vite-1.0.0.tgz","hashes":{"sha1":"e21fb6f15199acfca523ac51b81fac3a6e6d77b9","sha512_sri":"sha512-VOC4kxHvhGc9l/drGquGiU7rASgBrSvD4PcyQUBxjdY1eVE7w74Wi6iRBsHhuRcpLFOEaG4k/bwD2s63+Zn0Zw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/basic-vite/MAL-2026-11131.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}