CRITICAL npm Malware
Malicious code in vite-common-utils (npm)
MAL-2026-6088 · GHSA-6wm7-cff3-322r
Published · Modified
Dependency scanning
Check whether vite-common-utils is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (b1d3397d754ffeb3726496769b2f159ce8596b2233b5875afa8f7fbca29ed0fd)
The package presents itself as a Vite utility library but its only export, loadFilbetScriptSilently, creates a