← Back to Feed

Hackers target exposed Vite dev servers to steal AWS, Azure secrets

September 14, 2026 · BleepingComputer · Severity: MEDIUM

Attackers are actively scanning for exposed Vite development servers to steal AWS and Azure cloud credentials, exploiting Vite's default dev server configuration that binds to all interfaces without authentication.

Key Takeaways

  • Attackers are actively scanning for exposed Vite development servers to steal AWS and Azure cloud credentials from environment variables.
  • The campaign specifically targets Vite's dev server mode, which by default exposes configuration files containing cloud provider credentials.
  • Development teams should configure Vite servers to bind only to localhost and avoid storing production secrets in client-side environment variables.
☕ Buy a Coffee