{"id":2865,"date":"2026-09-15T14:57:20","date_gmt":"2026-09-15T14:57:20","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2865"},"modified":"2026-09-15T14:57:20","modified_gmt":"2026-09-15T14:57:20","slug":"mass-scanning-campaign-exploits-vite-flaw-to-extract-cloud-credentials-from-exposed-dev-servers","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2865","title":{"rendered":"Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 15, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Cloud Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgDvoBVfJIN7YwGuf64F0CQWt9GrAVzaxDWGJetCrAGM_QgGEfpZm_I7f3FTkWBydY7v_iV4n8RWPAr4jfp7ZhN9DVbVZGDryBYlZiL6dn5RuYzLd811NH_sARdjbwWIpf9kOj-jtXfLzb7BTuy-iMpHbsgB9n8J5T7Hx0qp0D1_XeJR-ANcGQ5p88YH3fE\/s1700-nu-rw-lo-l85-e365\/vite.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data.<\/p>\n<p>The first is an automated effort aimed at internet-exposed Vite development servers that&#8217;s designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per <a href=\"https:\/\/www.f5.com\/labs\/articles\/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-39364\" target=\"_blank\">F5 Labs<\/a>.<\/p>\n<p>The credential harvesting activity, observed in August 2026, has been found to leverage an exploit for CVE-2026-39364 (CVSS score: 8.2), a high-severity security flaw in Vite that could permit an unauthenticated attacker to bypass security restrictions via query parameter manipulation and leak sensitive data, including files specified by server.fs.deny.<\/p>\n<p>\u00abOn the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&amp;raw, or ?import&amp;url&amp;inline are appended,\u00bb Vite said in an <a href=\"https:\/\/github.com\/vitejs\/vite\/security\/advisories\/GHSA-v2wj-q39q-566r\" target=\"_blank\">advisory<\/a> for the flaw in April 2026.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Successful exploitation, however, requires three conditions to be met for an app to be deemed affected &#8211;<\/p>\n<p><a name=\"more\"\/><\/p>\n<ul>\n<li>Explicitly exposes the Vite dev server to the network using &#8211;host or server.host config option<\/li>\n<li>The sensitive file exists in the allowed directories specified by server.fs.allow<\/li>\n<li>The sensitive file is denied with a pattern that matches a file by server.fs.deny<\/li>\n<\/ul>\n<p>\u00abUnder default configurations, Vite binds to localhost,\u00bb F5 Labs said. \u00abWhen developers expose the service by passing the &#8211;host flag, setting server.host, or misconfiguring Docker container port mappings, the development server becomes directly reachable over the local network or public internet.\u00bb<\/p>\n<p>Attackers can issue an HTTP GET request to the \/@fs\/ endpoint, referencing a sensitive file path and appending bypass query parameters. This causes the server to process the request, while undermining the server.fs.deny check, and ultimately return the contents of the requested file in plaintext in the HTTP response body.<\/p>\n<p>This can have severe implications when the request is used to target configuration directories, granting the attackers unauthorized access to plaintext API secrets, database passwords, and cloud administrative credentials. F5 said it observed several requests consistent with the flaw to conduct reconnaissance and extract the following types of data &#8211;<\/p>\n<ul>\n<li>Environment configurations<\/li>\n<li>AWS credentials<\/li>\n<li>AWS configurations and backups<\/li>\n<li>Infrastructure state files (e.g., terraform.tfstate and serverless.yml)<\/li>\n<li>Azure profiles<\/li>\n<li>System memory and environment details (e.g., \/etc\/passwd, \/proc\/self\/environ, \/proc\/1\/environ, and \/proc\/self\/cwd\/.env)<\/li>\n<\/ul>\n<p>\u00abProbing \/proc\/self\/cwd\/.env demonstrates an understanding of the deployment stack, reading the active .env file relative to the running process without needing to guess the absolute web application path,\u00bb F5 said.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/event-security-need\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJkE4t8oCql1wmWVt687J1yD7WnYRqvIpcsUwFSVUO-0HpxZWMCxLmeYwBlz38-C0KD-R6f9Pg0swgPTQuBsNXck_Kl3iKWNSQtyMcDNUSZGhiBd_XFu6U1SQi5LhuW-FHg00iT3CbRCUgMoCwhZevwxp8-9gwM2wZVVtGVO8Z2NbZ5EjVmI2dH4adnSAk\/s728-nu-rw-lo-l85-e365\/Shai-Hulud-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The requests make use of bogus User-Agent headers impersonating major web crawlers and artificial intelligence bots, like Googlebot, ClaudeBot, GPTBot, PerplexityBot, OAI-SearchBot, and Amazonbot. The requests also inject forged X-Forwarded-For and X-Real-IP values (e.g., 34.94.237[.]62 and 104.28.219[.]193) to get around IP-based access lists and complicate log analysis.<\/p>\n<p>A significant chunk of the malicious activity has originated from the U.S., Belgium, the Netherlands, Singapore, and Taiwan, with the attackers using Google Cloud Platform ranges (34.x and 35.x) to fly under the radar.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 15, 2026Vulnerability \/ Cloud Security Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2866,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[6,329,446,1886,430,137,761,70,3417,777,2603],"class_list":["post-2865","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-campaign","tag-cloud","tag-credentials","tag-dev","tag-exploits","tag-exposed","tag-extract","tag-flaw","tag-massscanning","tag-servers","tag-vite"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2865","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2865"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2865\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2866"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2865"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2865"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2865"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}