Exposed Vite Dev Servers Targeted for Cloud Secrets
Score: 8/10

Exposed Vite Dev Servers Targeted for Cloud Secrets

Threat actors are mass-scanning for exposed Vite development servers to exploit CVE-2026-39364 and steal AWS and Azure credentials.

Executive Summary

A large-scale scanning campaign has been identified targeting internet-exposed Vite development servers to exfiltrate cloud credentials and sensitive configuration files. The campaign primarily exploits CVE-2026-39364, a high-severity flaw allowing unauthenticated attackers to bypass file access controls by manipulating HTTP GET query parameters. F5 Labs observed over 32,000 raw events related to this activity, originating largely from Google Cloud IP ranges to evade detection.

The attack chain involves identifying exposed servers (often due to the --host flag or misconfigured Docker ports) and requesting sensitive files like .env files, AWS/Azure credentials, and Terraform state files. The vulnerability affects Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5.

This activity poses a significant risk to cloud environments, as the stolen credentials provide a direct path for cloud account takeover. Organizations using Vite for development should ensure servers are not publicly accessible and rotate any secrets that may have been exposed on vulnerable instances.

Key Details

Threat Name

CVE-2026-39364

Affects

Vite versions 7.1.0 through 7.3.2, Vite 8.x before 8.0.5, Vite

Adversary

—

MITRE Techniques

Malware/Tools

GrayRabbit, EtherHiding, Cerber

Report Score

8out of 10
Quality Score
Good
IOC Quality6
TTP Details8
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth7

Sources