OpenSSF/OSV advisory MAL-2026-16474 confirms this npm version as malicious. The package presents as a Vite dev-server wrapper but its declared postinstall (`node./postinstall-run.cjs`) chains through `lib/gradle/lifecycle/postinstall-entry.cjs` and `instrumentation-registry.cjs` to base64+AES-256-GCM-decrypt an embedded ciphertext in `agent-bytecode.segments.cjs`. The AES key is derived from SHA-256 of a specific victim workspace's files (package.json, pnpm-workspace.yaml,...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source invokes a package manager install command at runtime.
bin/cli.jsView on unpkg · L27This report applies to vite-dev-launcher@2.9.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source invokes a package manager install command at runtime.
bin/cli.jsView on unpkg · L27