https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/
Exposed Vite dev servers hit in credential-harvesting campaign Attackers are mass-scanning internet-exposed Vite development servers to exploit CVE-2026-39364 , a file access bypass affecting Vite 7.1.0–7.3.2 and 8.x before 8.0.5. F5 logged more than 800 attacks and roughly 32,000 raw events in a month, with requests targeting .env files, AWS and Azure credentials, Terraform state