-= Per source details. Do not edit below this line.=-
The npm package 'viteplugiin' impersonates '@base44/viteplugin' via a one-character insertion (doubled 'i') and ships a hostile payload in dist/index.js, the entry resolved by the package's exports map. After the legitimate-looking plugin code, a large whitespace gap conceals an obfuscated stub that uses Fisher-Yates string shuffles with hardcoded seeds to reconstruct the identifiers 'require', '__dirname', '__filename', 'undefined', and 'constructor', reassigns require/__dirname/__filename onto the global object, obtains the Function constructor, and invokes it on two decoded string bodies — executing attacker-controlled JavaScript at module load time in the consumer's Vite build. Because Vite configs import plugins at config-evaluation time, adding this plugin to vite.config.* causes the payload to run on developer and CI machines during any Vite command. Provenance is consistent with an attack drop: empty author field, no repository/homepage, and package.json 'main' pointing at a nonexistent root index.js while the exports map silently routes '.' to the tampered dist/index.js. The README and internal resolveId targets reference the legitimate '@base44/vite-plugin' as cover.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-010390",
"import_time": "2026-07-14T04:32:00.518400882Z",
"modified_time": "2026-07-14T04:13:11Z",
"sha256": "5afbe0fab50b9582867bb208b6cfb20080849e27d27df79711f55e2db69f66bb",
"source": "amazon-inspector",
"versions": [
"1.0.28"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "972a3eafd8c28671cbd02a166fa8bf17cedc6cd31f66ff8e95a04e026f875639",
"tlsh": "a5117830cc65cc9315c492a29df95283a57a085b8c40fe0433e2162d0f9caaf31bb66c"
},
{
"path": "dist/index.js",
"sha256": "f0bbe9b553d38cb1f7d4ab85d7aa49f06bda1e1a1720cbb29001d976e6bfbe79",
"tlsh": "b7725d6f24f530220f63bc64874f0016b63a8717995dea04774dc3686fa915caab37dc"
}
],
"package_integrity": [
{
"filename": "viteplugiin-1.0.28.tgz",
"hashes": {
"sha1": "145c9731d27ed2d3eaf00d1e0aff0504b214627f",
"sha512_sri": "sha512-ii2ceIIrjlSWEXQ+VmT6IVAgJd22oKswyWNWV+IITYaXT+gZTrU7HBEI1nxpP/fGbTryy7CIrAFbpCOpZ72xag=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/viteplugiin/MAL-2026-10546.json"