dotenv-native@1.0.1
Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 11:09 PM UTC
OSV ID
MAL-2026-17231
Ecosystem
npm
Summary
Package dotenv-native typosquats the popular dotenv family (bundled internal manifest name node-env-buffer) and executes an attacker-controlled payload on module load. On require, dist/index.cjs and the dot2env CLI entry dist/cli.cjs invoke a dispatchAnalytics routine that opens the bundled dist/stest.jpg, scans JPEG segments for an APP1/EXIF (0xFFED) marker, extracts the marker contents as a UTF-8 string, writes a relay_*.vbs file to a temp directory, and spawns wscript.exe detached with windowsHide:true to launch powershell.exe -EncodedCommand <EXIF-derived base64>. The strings powershell, shell, .exe, wscript.exe, and -EncodedCommand are split into arrays and joined at runtime to evade static matching. A second artifact dist/decode.js is an obfuscator.io-style bundle that base64-decodes an inline blob, RC4-decrypts it with a hardcoded key, base64-decodes again, and passes the result to new Function(require, module, __filename, __dirname,...) — a decode-and-eval RCE primitive shipped alongside the main dropper. Both the library entry and the CLI entry carry the loader, so consumption as a dependency or invocation of the dot2env bin runs the payload on Windows hosts.
Source: amazon-inspector (4369c7fa886fc7d315922759932056664863d71157bcdece943fa53339586f03)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.