Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the @vite-pro/vite-ui package.
@vite-pro/vite-ui is a malicious package. This package contains malicious code and is part of a campaign targeting developers using Vite. When imported into an application, it downloads and executes a remote access trojan (RAT), enabling attackers to execute arbitrary commands, steal credentials and files, and establish persistent access to the affected system.
Note: The package impersonates legitimate Vite-related packages but is not affiliated with the Vite project or its maintainers.