Togoder security

npm package security report

vite@8.3.2 security report

Risky patterns found that deserve a look.

Needs review Version 8.3.2 Files reviewed 13 Size 653.6 KB Scanned

Summary

Togoder Security scanned the npm package vite@8.3.2 on Oct 6, 2026. An AI review of 13 source files produced 3 medium, 12 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
12
low

Findings 15

medium

Dynamic code execution

NPS-D85EB2E98C36

The ESModulesEvaluator class uses new AsyncFunction(...) to execute module code dynamically via runInlinedModule. This constructs and runs a function at runtime from string input, which is a known pattern for arbitrary code execution if the code source is not fully trusted.

dist/node/module-runner.js
medium

Dynamic module loading

NPS-FF3D78986749

ESModulesEvaluator.runExternalModule(filepath) calls import(filepath) where filepath is derived from server-fetched module metadata (fetchedModule.externalize). This dynamic import of a computed value could load arbitrary modules if the transport source is untrusted.

dist/node/module-runner.js
medium

Dynamic import registration

NPS-36C0DAE8BED3

createImportMetaResolver() calls module.register(hookModuleContent) and module.registerHooks(...) to register a custom module resolution hook at runtime, altering Node's module resolution behavior.

dist/node/module-runner.js
low

top-level code execution

NPS-795B078C40C7

Top-level code runs at import/execution time, including setting a global start time, parsing debug/profile arguments, and invoking start(), which is normal for a CLI shim.

bin/vite.js:1
low

compile cache manipulation

NPS-AD98FE6B26DC

module.enableCompileCache and module.flushCompileCache are used to improve startup performance. These are Node built-ins and do not indicate malicious behavior.

bin/vite.js:68
low

dynamic import

NPS-1D3D44C87DA8

The script dynamically imports '../dist/node/cli.js' relative to the launcher, which is expected behavior for a CLI entry point and not externally controlled.

bin/vite.js:78
low

inspector/profiler usage

NPS-69DBD8C8CF71

When --profile is passed, the script enables Node's inspector and starts CPU profiling. This is a documented Vite feature and does not exfiltrate data or execute untrusted code.

bin/vite.js:88
low

Dynamic code execution

NPS-00B300130403

Uses Function("return this")() as a fallback to obtain the global object. While this is a common pattern for cross-environment global detection, it constitutes dynamic code execution and can be blocked by strict Content Security Policy (CSP) environments.

dist/client/env.mjs:6
low

Global object pollution

NPS-889140FCD4DF

Iterates over keys in __DEFINES__ and writes values onto the global context (globalThis/window/self). Nested keys create or mutate global objects. This could be abused to overwrite security-sensitive globals if __DEFINES__ is attacker-controlled or misconfigured, though typically it is a compile-time constant injected by the bundler.

dist/client/env.mjs:8
low

File system manipulation outside package scope

NPS-53D3EB368EE3

The stopProfiler function writes CPU profile files to the current working directory using fs.writeFileSync with a path resolved from the current directory (path.resolve('./${fileName}.cpuprofile')). While this is standard behavior for Vite's profiling feature and the filename is controlled via a global variable, writing files to the CWD based on an environment-controlled global (global.__vite_profile_name) could potentially be abused if that global is set to a path traversal value, though path.resolve would still constrain to CWD-relative paths in most cases.

dist/node/cli.js
low

Dynamic imports based on internal module paths

NPS-93A04DE10561

Multiple dynamic imports are used (import('./chunks/node.js'), import('node:inspector')) to lazily load modules. These are resolved from static string literals and internal relative paths, not from external or computed input, so risk is minimal. However, the pattern of dynamic module loading is worth noting.

dist/node/cli.js
low

Global state mutation via process globals

NPS-5E7539FCAB9A

Reads and writes to global.__vite_profile_session and global.__vite_profile_name, which influence profiler file naming. If external code can manipulate these globals (e.g., via a malicious config), it could influence file paths. No credential harvesting or exfiltration is present.

dist/node/cli.js
low

JSON parsing of remote/transformed content

NPS-A99886BC0094

Source maps are extracted from module code via regex and parsed with JSON.parse(decodeBase64(...)) in getModuleSourceMapById, and later new DecodedMap(...) operates on that data. This is generally expected behavior for a module runner, but parsing external data is a potential vector.

dist/node/module-runner.js
low

Dynamic RPC/transport invocation

NPS-1CF08B11F3C1

The createInvokeableTransport and normalizeModuleRunnerTransport implement an RPC mechanism over the transport (vite:invoke), and getModuleInformation invokes fetchModule with URL/importer arguments. This is network-based code loading driven by computed values, which is a pattern to verify carefully against the package's stated purpose.

dist/node/module-runner.js
low

Sourcemap interceptor / Error.prepareStackTrace override

NPS-DE1657BBBC90

interceptStackTrace overrides Error.prepareStackTrace globally, which can affect diagnostics and is an invasive runtime change, though common for sourcemap tooling.

dist/node/module-runner.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/client/env.mjs medium Code performs runtime global-object detection using Function() and injects build-time defines onto the global scope, but shows no evidence of data exfiltration, credential harvesting, or other malicious behavior.
dist/node/cli.js medium This appears to be the legitimate Vite CLI entry point with standard dev server, build, optimize, and preview commands; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were detected, though minor filesystem writes to CWD and dynamic imports warrant low-severity notes.
dist/node/module-runner.js medium This is Vite's module-runner implementation that legitimately uses new AsyncFunction, dynamic import, and RPC transport to execute transformed modules; the patterns are consistent with its documented role but do involve dynamic code execution and dynamic module loading that carry inherent risk if the transport source is untrusted.
bin/openChrome.js safe Legitimate macOS JXA script from create-react-app for opening URLs in Chrome, with no malicious patterns detected.
bin/vite.js safe The file is a standard Vite CLI launcher with development-oriented flags and no signs of malicious behavior such as data exfiltration, credential harvesting, obfuscation, mining, backdoors, or suspicious process spawning.
dist/client/bundledDevClient.mjs safe This is a standard Vite HMR client bundle with no malicious patterns detected.
dist/client/client.mjs safe This is the standard Vite HMR client runtime; no malicious patterns, exfiltration, credential harvesting, or unauthorized code execution were detected.
dist/node/chunks/lib.js safe No malicious patterns detected; the file is a bundled copy of the benign postcss-value-parser library with no network, filesystem, process execution, or obfuscated code.
dist/node/chunks/postcss-import.js safe The code is a bundled copy of the legitimate postcss-import package (v16.2.0) that performs CSS @import resolution and inlining with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, network exfiltration, or process spawning.
dist/node/index.js safe The file is a standard Vite distribution re-export module containing only imports and exports of legitimate build-tool APIs, with no malicious patterns, obfuscation, dynamic code execution, or suspicious network/file/process activity.
dist/node/internal.js safe No malicious patterns detected
misc/false.js safe Cleared by Jev triage; no further analysis needed
misc/true.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is vite safe to use?

No confirmed malware was found in vite@8.3.2, but the review flagged 3 medium, 12 low severity findings for risky patterns worth checking before you rely on it.

Does vite contain malware?

No malware was identified in vite@8.3.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was vite checked?

Togoder Security downloaded the published npm package and had an AI model read its 13 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan vite together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in vite@8.3.2, cost nothing.

Related security reports