npm

dotenv-extend @3.3.5

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 12:32 PM UTC

Malicious

OSV ID

MAL-2025-192743

Ecosystem

npm

Summary

The package dotenv-extend was found to contain malicious code.

Source: amazon-inspector (b36b33fa03b9dafefe167d7891f649dc39ac77a18a67a25c44d0d647dd3518e9)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.