Hackers are running a mass-scanning campaign against internet-exposed Vite development servers in an effort to steal cloud credentials and configuration data from AWS and Azure deployments. The operation exploits CVE-2026-39364, a high-severity vulnerability affecting Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.