MAL-2026-6088

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/vite-common-utils/MAL-2026-6088.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6088
Aliases
  • GHSA-6wm7-cff3-322r
Published
2026-06-17T22:33:52Z
Modified
2026-08-20T22:01:46Z
Summary
Malicious code in vite-common-utils (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (b1d3397d754ffeb3726496769b2f159ce8596b2233b5875afa8f7fbca29ed0fd)

The package presents itself as a Vite utility library but its only export, loadFilbetScriptSilently, creates a

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-006958",
            "import_time": "2026-06-17T22:38:22.614222187Z",
            "modified_time": "2026-06-17T22:33:58Z",
            "sha256": "1cee011bd6bf55f3c74e2e42c15a9df8f1f7974308da228087ba019c3e5cd831",
            "source": "amazon-inspector",
            "versions": [
                "1.0.5"
            ]
        },
        {
            "id": "IN-MAL-2026-006956",
            "import_time": "2026-06-17T22:38:22.387689707Z",
            "modified_time": "2026-06-17T22:33:52Z",
            "sha256": "b1d3397d754ffeb3726496769b2f159ce8596b2233b5875afa8f7fbca29ed0fd",
            "source": "amazon-inspector",
            "versions": [
                "1.0.4"
            ]
        },
        {
            "id": "IN-MAL-2026-006957",
            "import_time": "2026-06-17T22:38:22.509457726Z",
            "modified_time": "2026-06-17T22:33:53Z",
            "sha256": "c989aa0727b9dd8a6ee9cc42b851dcea293df2ea4129284d43b4476461d91bcb",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "id": "GHSA-6wm7-cff3-322r",
            "import_time": "2026-08-20T13:33:26.041953091Z",
            "modified_time": "2026-08-20T13:05:33Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "SEMVER"
                }
            ],
            "sha256": "e8394deefe81eda6ab98a6b2e3c06d428d03ace2d311e544cdbc04d78909d01a",
            "source": "ghsa-malware"
        },
        {
            "id": "IN-MAL-2026-018465",
            "import_time": "2026-08-20T21:43:25.459627873Z",
            "modified_time": "2026-08-20T21:14:45Z",
            "sha256": "0c83e52482901a9e4a71857d42091494f5efb2dadfb46b94292719a6fd9beca3",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-018467",
            "import_time": "2026-08-20T21:43:25.595813593Z",
            "modified_time": "2026-08-20T21:15:01Z",
            "sha256": "b7c4725309f3e8116f5a6e58452c9970ca6f8751ee0c4b7f5547e83bb11ba1bb",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-018463",
            "import_time": "2026-08-20T21:43:25.280279929Z",
            "modified_time": "2026-08-20T21:14:30Z",
            "sha256": "befb3eb8831a4de704bc99b3bf64c5be7c997f2af0c5553efcd154e1f2757d60",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / vite-common-utils

Package

Name
vite-common-utils
View open source insights on deps.dev
Purl
pkg:npm/vite-common-utils

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "dist/index.js",
            "sha256": "f0ab475fbfa816f3a76bd4c314c16999ab9f8d349147605b4b083f7b29fe6a29",
            "tlsh": "18313a952d40ad9063964fbe7677f1d8c266dc7e28d508c9e0a979c87d20a30f4e2774"
        }
    ],
    "package_integrity": [
        {
            "filename": "vite-common-utils-1.0.5.tgz",
            "hashes": {
                "sha1": "0375e5987c718eaca90a7297d0a3e2561014da32",
                "sha512_sri": "sha512-lEZIrcfysLQ4EKuiQzhUnJ5qFZb49pe6maCNWW3yqCSYWZ5StX5fGEITNqYq1I88ylnUcsgFIAH9IwXYJbeaxQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/vite-common-utils/MAL-2026-6088.json"