Attackers Are Scanning for Exposed Vite Dev Servers to Steal Cloud Credentials
Security researchers at F5 Labs have detailed an automated scanning campaign targeting internet-exposed Vite development servers, aimed at stealing cloud credentials and sensitive configuration data from AWS, Azure and infrastructure state files. The campaign, observed in August 2026, exploits CVE-2026-39364, a high-severity flaw in Vite that lets an unauthenticated attacker bypass security restrictions by manipulating query parameters in HTTP requests.
Normally, Vite blocks access to sensitive files such as .env and certificate files through a setting called server.fs.deny. However, by appending specific query parameters to requests, attackers can trick the server into returning these files in plaintext. This becomes a serious risk when a development server has been exposed to the local network or the internet, for example by using the --host flag, changing server.host settings, or misconfiguring Docker port mappings, since Vite binds to localhost by default and is not meant to be publicly reachable.
F5 Labs observed attackers using this technique to probe for API secrets, database passwords and cloud administrative credentials, including requests designed to identify the underlying deployment stack without needing to guess file paths. This kind of reconnaissance can give attackers a direct route into cloud environments if credentials are successfully harvested.