Hackers use a mass-scanning campaign to target internet-exposed Vite development servers in order to steal sensitive cloud data. Reporting from multiple outlets says the attackers aim to obtain credentials and configuration information from deployments running on Amazon Web Services (AWS) and Microsoft Azure, alongside related infrastructure artifacts.

Security researchers attribute the activity to exploitation of a Vite-related issue, and describe an automated process designed to identify vulnerable instances and extract data from them. One report frames the campaign as siphoning cloud credentials and configuration values, while also attempting to capture infrastructure state files, which can contain details needed to manage or recreate cloud resources.

Across the coverage, the core focus is the same: exposed Vite dev environments are being scanned at scale, and the extracted information is tied to AWS and Azure accounts and infrastructure settings. The outlets differ mainly in emphasis, with one highlighting the credential-stealing objective and the other discussing the broader exploitation workflow, including attempts to obtain infrastructure state files.