Hackers target exposed Vite dev servers to steal AWS, Azure secrets
Reported exploitedViteOur summary
Attackers are actively exploiting a high-severity vulnerability in Vite development servers to extract sensitive cloud credentials and configuration files from AWS and Azure environments. The campaign targets unpatched instances of versions 7.1.0 through 7.3.2, as well as the 8.x branch prior to 8.0.5, using CVE-2026-39364 to bypass file access controls.
F5 detected over 800 distinct attack attempts over one month, noting that adversaries leverage specific query parameters to read protected files in plaintext. Upon successful access, attackers systematically probe for environment variables, Terraform states, and service account tokens. Organizations running publicly exposed Vite servers should update to the latest version and rotate any potentially compromised secrets.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.