23 heuristic finding(s) in vite@7.1.2 — review recommended (AI second opinion unavailable).
AI breakdown
Plain-English summary of what this package does and how it behaves.
Native-ESM powered web dev build tool
Capabilities
- Provides a command-line executable
- Spawns child processes
- Contains obfuscated/encoded code
Data access
- None observed in static analysis
Network
- Makes outbound network requests
Static analysis raised 23 finding(s). Review the details below before installing.
Dependency & execution chain
Every package this one pulls in, colored by verdict. Expand to walk the tree.
Security findings (23)
Static analysis rule matches, with the exact code that triggered them.
Version mismatch in types/package.json
Multiple obfuscation patterns in dist/node/chunks/dep-Du_AlPMa.js
Multiple obfuscation patterns in package/dist/node/chunks/dep-Du_AlPMa.js
Multiple obfuscation patterns in dist/node/chunks/dep-V5uAjiuB.js
Multiple obfuscation patterns in package/dist/node/chunks/dep-V5uAjiuB.js
Multiple obfuscation patterns in dist/node/module-runner.js
Multiple obfuscation patterns in package/dist/node/module-runner.js
File dist/node/chunks/dep-BDCsDwBr.js contains a hardcoded public IP (0000:0000:0000:0000:0000:0000:0000:0001) used in network code — review for hidden exfiltration or C2 endpoints.
File package/dist/node/chunks/dep-BDCsDwBr.js contains a hardcoded public IP (0000:0000:0000:0000:0000:0000:0000:0001) used in network code — review for hidden exfiltration or C2 endpoints.
File dist/node/chunks/dep-Du_AlPMa.js combines network access with process execution
File dist/node/chunks/dep-Du_AlPMa.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.
File dist/node/chunks/dep-Du_AlPMa.js builds a dynamic import/require argument alongside network access — possible remote module loading.
File package/dist/node/chunks/dep-Du_AlPMa.js combines network access with process execution
File package/dist/node/chunks/dep-Du_AlPMa.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.
File package/dist/node/chunks/dep-Du_AlPMa.js builds a dynamic import/require argument alongside network access — possible remote module loading.
File dist/node/module-runner.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.
File package/dist/node/module-runner.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.
File dist/client/client.mjs combines network access with process execution
File dist/client/client.mjs builds a dynamic import/require argument alongside network access — possible remote module loading.
File package/dist/client/client.mjs combines network access with process execution
File package/dist/client/client.mjs builds a dynamic import/require argument alongside network access — possible remote module loading.
File dist/node/index.d.ts builds a dynamic import/require argument alongside network access — possible remote module loading.
File package/dist/node/index.d.ts builds a dynamic import/require argument alongside network access — possible remote module loading.
Known vulnerabilities (8)
Published CVEs / advisories affecting this version.
vite: `server.fs.deny` bypass on Windows alternate paths
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
Vite: `server.fs.deny` bypassed with queries
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling
vite allows server.fs.deny bypass via backslash on Windows
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
Vite middleware may serve files starting with the same name with the public directory
Vite's `server.fs` settings were not applied to HTML files
Files in package (76)
How ShadowCanopy checks npm packages
ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.
This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/vite