npm package intelligence

vite — deep security report

ShadowCanopy's full breakdown of vite on npm: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Safe to use
Deep-scanned by ShadowCanopy — no threats found in its code, dependencies, or network behavior.
Scanned 9/12/2026
Approvedvite@8.3.0View on registry ↗latest: 8.3.0

Vite 8.3.0 is legitimate. All flagged patterns (Function constructors,  /Ā regexes, base64/WASM blobs, atob/Buffer, exec+fetch) come from bundled third-party code (lodash, parse5, entities, sourcemap libs) and Vite's own module-runner/HMR logic. No malicious sinks, exfiltration, or hidden payloads present.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

Vite is a native-ESM powered web dev build tool for serving, bundling, and building frontend applications.

Capabilities

  • Provides CLI via bin/vite.js
  • Runs build and dev scripts using rolldown and TypeScript
  • Bundles client and node modules into dist
  • Processes CSS via PostCSS and LightningCSS dependencies

Data access

  • Filesystem

Network

  • No network access observed

Widely used legitimate package; static findings of obfuscation, remote fetch, and dynamic loads likely stem from minified/bundled dist files rather than malicious intent.

Dependency & execution chain

Every package this one pulls in, colored by verdict. Expand to walk the tree.

13 packages6 direct
vite@8.3.024 findings
postcss@8.5.282 findings
rolldown@1.2.96 findings
picomatch@4.0.72 findings
tinyglobby@0.2.17
lightningcss@1.33.0

Security findings (24)

Static analysis rule matches, with the exact code that triggered them.

mediumObfuscated source fileATK-023dist/node/chunks/build.js

Multiple obfuscation patterns in dist/node/chunks/build.js

mediumObfuscated source fileATK-023package/dist/node/chunks/build.js

Multiple obfuscation patterns in package/dist/node/chunks/build.js

mediumObfuscated source fileATK-023dist/node/chunks/dist.js

Multiple obfuscation patterns in dist/node/chunks/dist.js

mediumObfuscated source fileATK-023package/dist/node/chunks/dist.js

Multiple obfuscation patterns in package/dist/node/chunks/dist.js

mediumObfuscated source fileATK-023dist/node/module-runner.js

Multiple obfuscation patterns in dist/node/module-runner.js

mediumObfuscated source fileATK-023package/dist/node/module-runner.js

Multiple obfuscation patterns in package/dist/node/module-runner.js

highRemote fetch with process executionATK-024dist/client/bundledDevClient.mjs

File dist/client/bundledDevClient.mjs combines network access with process execution

highDynamic module load with remote sourceATK-027dist/client/bundledDevClient.mjs

File dist/client/bundledDevClient.mjs builds a dynamic import/require argument alongside network access — possible remote module loading.

highRemote fetch with process executionATK-024package/dist/client/bundledDevClient.mjs

File package/dist/client/bundledDevClient.mjs combines network access with process execution

highDynamic module load with remote sourceATK-027package/dist/client/bundledDevClient.mjs

File package/dist/client/bundledDevClient.mjs builds a dynamic import/require argument alongside network access — possible remote module loading.

highRemote fetch with process executionATK-024dist/client/client.mjs

File dist/client/client.mjs combines network access with process execution

highDynamic module load with remote sourceATK-027dist/client/client.mjs

File dist/client/client.mjs builds a dynamic import/require argument alongside network access — possible remote module loading.

highRemote fetch with process executionATK-024package/dist/client/client.mjs

File package/dist/client/client.mjs combines network access with process execution

highDynamic module load with remote sourceATK-027package/dist/client/client.mjs

File package/dist/client/client.mjs builds a dynamic import/require argument alongside network access — possible remote module loading.

highRemote fetch with process executionATK-024dist/node/chunks/build.js

File dist/node/chunks/build.js combines network access with process execution

highDecoded payload executedATK-026dist/node/chunks/build.js

File dist/node/chunks/build.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.

highDynamic module load with remote sourceATK-027dist/node/chunks/build.js

File dist/node/chunks/build.js builds a dynamic import/require argument alongside network access — possible remote module loading.

highRemote fetch with process executionATK-024package/dist/node/chunks/build.js

File package/dist/node/chunks/build.js combines network access with process execution

highDecoded payload executedATK-026package/dist/node/chunks/build.js

File package/dist/node/chunks/build.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.

highDynamic module load with remote sourceATK-027package/dist/node/chunks/build.js

File package/dist/node/chunks/build.js builds a dynamic import/require argument alongside network access — possible remote module loading.

highDynamic module load with remote sourceATK-027dist/node/index.d.ts

File dist/node/index.d.ts builds a dynamic import/require argument alongside network access — possible remote module loading.

highDynamic module load with remote sourceATK-027package/dist/node/index.d.ts

File package/dist/node/index.d.ts builds a dynamic import/require argument alongside network access — possible remote module loading.

highDecoded payload executedATK-026dist/node/module-runner.js

File dist/node/module-runner.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.

highDecoded payload executedATK-026package/dist/node/module-runner.js

File package/dist/node/module-runner.js decodes a base64/hex blob and passes it to an execution sink — a common way to hide a malicious payload.

Package metadata

LicenseMIT

Native-ESM powered web dev build tool

Homepage ↗Repository ↗

Files in package (72)

LICENSE.mdpackage/LICENSE.mdREADME.mdpackage/README.mdbin/openChrome.jspackage/bin/openChrome.jsbin/vite.jspackage/bin/vite.jsclient.d.tspackage/client.d.tsdist/client/bundledDevClient.mjspackage/dist/client/bundledDevClient.mjsdist/client/client.mjspackage/dist/client/client.mjsdist/client/env.mjspackage/dist/client/env.mjsdist/node/chunks/build.jspackage/dist/node/chunks/build.jsdist/node/chunks/dist.jspackage/dist/node/chunks/dist.jsdist/node/chunks/lib.jspackage/dist/node/chunks/lib.jsdist/node/chunks/moduleRunnerTransport.d.tspackage/dist/node/chunks/moduleRunnerTransport.d.tsdist/node/chunks/postcss-import.jspackage/dist/node/chunks/postcss-import.jsdist/node/cli.jspackage/dist/node/cli.jsdist/node/index.d.tspackage/dist/node/index.d.tsdist/node/index.jspackage/dist/node/index.jsdist/node/internal.d.tspackage/dist/node/internal.d.tsdist/node/internal.jspackage/dist/node/internal.jsdist/node/module-runner.d.tspackage/dist/node/module-runner.d.tsdist/node/module-runner.jspackage/dist/node/module-runner.js

How ShadowCanopy checks npm packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/vite