Vite 8.3.0 is legitimate. All flagged patterns (Function constructors, /Ā regexes, base64/WASM blobs, atob/Buffer, exec+fetch) come from bundled third-party code (lodash, parse5, entities, sourcemap libs) and Vite's own module-runner/HMR logic. No malicious sinks, exfiltration, or hidden payloads present.
AI breakdown
Plain-English summary of what this package does and how it behaves.
Vite is a native-ESM powered web dev build tool for serving, bundling, and building frontend applications.
Capabilities
- Provides CLI via bin/vite.js
- Runs build and dev scripts using rolldown and TypeScript
- Bundles client and node modules into dist
- Processes CSS via PostCSS and LightningCSS dependencies
Data access
- Filesystem
Network
- No network access observed
Widely used legitimate package; static findings of obfuscation, remote fetch, and dynamic loads likely stem from minified/bundled dist files rather than malicious intent.
Dependency & execution chain
Every package this one pulls in, colored by verdict. Expand to walk the tree.
Security findings (24)
Static analysis rule matches, with the exact code that triggered them.
Multiple obfuscation patterns in dist/node/chunks/build.js
Multiple obfuscation patterns in package/dist/node/chunks/build.js
Multiple obfuscation patterns in dist/node/chunks/dist.js
Multiple obfuscation patterns in package/dist/node/chunks/dist.js
Multiple obfuscation patterns in dist/node/module-runner.js
Multiple obfuscation patterns in package/dist/node/module-runner.js
File dist/client/bundledDevClient.mjs combines network access with process execution
File dist/client/bundledDevClient.mjs builds a dynamic import/require argument alongside network access — possible remote module loading.
File package/dist/client/bundledDevClient.mjs combines network access with process execution
File package/dist/client/bundledDevClient.mjs builds a dynamic import/require argument alongside network access — possible remote module loading.
File dist/client/client.mjs combines network access with process execution
File dist/client/client.mjs builds a dynamic import/require argument alongside network access — possible remote module loading.
File package/dist/client/client.mjs combines network access with process execution
File package/dist/client/client.mjs builds a dynamic import/require argument alongside network access — possible remote module loading.
File dist/node/chunks/build.js combines network access with process execution
File dist/node/chunks/build.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.
File dist/node/chunks/build.js builds a dynamic import/require argument alongside network access — possible remote module loading.
File package/dist/node/chunks/build.js combines network access with process execution
File package/dist/node/chunks/build.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.
File package/dist/node/chunks/build.js builds a dynamic import/require argument alongside network access — possible remote module loading.
File dist/node/index.d.ts builds a dynamic import/require argument alongside network access — possible remote module loading.
File package/dist/node/index.d.ts builds a dynamic import/require argument alongside network access — possible remote module loading.
File dist/node/module-runner.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.
File package/dist/node/module-runner.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.
Files in package (72)
How ShadowCanopy checks npm packages
ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.
This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/vite