Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

2026-07-17T19:24:10Z5022b02bcb8fb7bbbf6e20376c064e606f6f169693a7e269a6286c37a2b7f535
ACR StealerAI securityAWSCISA KEVChainVeilClickLockDigiCertGoSerpentKubernetesNadMeshOkoBotSharePoint RCETELEPUZViteagent data-injectionblockchain C2botnetcloud keyscode-signing theftexposed AI servicesinfostealern8n token-exchange flawnpmsupply-chainzero-day

What happened

A broad set of active threats and high-impact vulnerabilities was reported: a supply-chain campaign (ViteVenom) delivered seven malicious npm packages for the Vite ecosystem using a multi-tier blockchain C2 (ChainVeil); a new NadMesh Go botnet is scanning exposed AI services and claiming thousands of AWS keys/Kubernetes tokens; a GoldenEyeDog subgroup (CylindricalCanine) is tied to DigiCert code‑signing certificate theft; multiple new malware families and campaigns (GoSerpent, TELEPUZ, ClickLock, ACR Stealer, OkoBot, TuxBot evolution) are stealing credentials, browser tokens, wallets and exfil

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5022b02bcb8fb7bbbf6e20376c064e606f6f169693a7e269a6286c37a2b7f535
Enrichment time
2026-07-17T19:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT · Baitaphish