Exposed Vite Dev Servers Leak AWS and Azure Keys
BleepingComputer reports F5 honeypots watching a mass-scan of internet-exposed Vite development servers that steal AWS and Azure credentials. The campaign uses CVE-2026-39364 in Vite 7.1.0 through 7.3.2 and 8.x before 8.0.5. F5 counted more than 800 attacks and about 32,000 raw events over a month.

BleepingComputer (Bill Toulas, 14 September 2026) reports a mass-scanning campaign against internet-exposed Vite development servers that tries to steal AWS and Azure credentials and configs. F5 spotted the activity on its honeypot sensors.
This is F5 sensor observation of exploitation attempts, as BleepingComputer wrote it up. It is not a named APT attribution, and it is not a CISA Known Exploited Vulnerabilities listing for CVE-2026-39364.
The exploit is CVE-2026-39364, a high-severity file-read and access-control bypass in Vite 7.1.0 through 7.3.2, and in the 8.x line before 8.0.5. The flaw was disclosed on 7 April. An unauthenticated attacker appends query parameters such as ?raw, ?import&raw, or ?import&url&inline, and the server then skips deny-list filtering and serves the target file in plaintext with HTTP 200.
F5 counted more than 800 attacks and about 32,000 raw events over a month. After a foothold, the scans hunt .env files, AWS credential and config paths, Azure tokens, Terraform and serverless state, and /proc environ files. The same source IPs also used CVE-2025-30208, CVE-2025-31125 (already flagged as actively exploited), and CVE-2024-45811.
Vite normally binds to localhost. Exposure happens through --host, server.host, or a Docker port map that puts 5173 on the internet. Observed traffic came from the United States, Belgium, and the Netherlands on Google Cloud IP ranges. F5 named 34.14.15.105, 34.16.200.129, and 34.11.196.206 as the most active addresses and as blocklist candidates.
Honeypot hits show scanning and exploit attempts. They do not prove every public Vite instance was emptied. F5's advice is to update to a patched Vite, block port 5173 from the internet, block suspicious /@fs/ requests, and rotate secrets if a vulnerable server was publicly exposed.
Related cloud-secret tape includes Azure data advertised against Fortune 500 names, Cyberpresso's secrets-management shortlist, and Microsoft passkey lures into Microsoft 365 cloud theft.
If any Vite 7.1 through 7.3.2 or 8.x before 8.0.5 was bound beyond localhost, patch now, close 5173 to the internet, and rotate AWS and Azure keys that sat on that host.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free