Vite Vulnerability Exploited in Mass-Scanning Campaign to Steal Cloud Credentials from Exposed Development Servers
A mass-scanning campaign exploits a high-severity Vite vulnerability (CVE-2026-39364) to extract cloud credentials and infrastructure data from exposed development servers by manipulating query parameters to bypass file access restrictions. The attack targets AWS and Azure configurations, leveraging misconfigured Vite dev servers to access sensitive files like .env and terraform state files.
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data.
The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs.
The
*** END OF TRANSMISSION ***