npm
Malicious dotenv-extend @3.3.5
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 12:32 PM UTC
OSV ID
MAL-2025-192743
Ecosystem
npm
Summary
The package dotenv-extend was found to contain malicious code.
Source: amazon-inspector (b36b33fa03b9dafefe167d7891f649dc39ac77a18a67a25c44d0d647dd3518e9)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.