Executive Summary
A large-scale scanning campaign has been identified targeting internet-exposed Vite development servers to exfiltrate cloud credentials and sensitive configuration files. The campaign primarily exploits CVE-2026-39364, a high-severity flaw allowing unauthenticated attackers to bypass file access controls by manipulating HTTP GET query parameters. F5 Labs observed over 32,000 raw events related to this activity, originating largely from Google Cloud IP ranges to evade detection.
The attack chain involves identifying exposed servers (often due to the --host flag or misconfigured Docker ports) and requesting sensitive files like .env files, AWS/Azure credentials, and Terraform state files. The vulnerability affects Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5.
This activity poses a significant risk to cloud environments, as the stolen credentials provide a direct path for cloud account takeover. Organizations using Vite for development should ensure servers are not publicly accessible and rotate any secrets that may have been exposed on vulnerable instances.
