Logo
npm

dotenv-promises@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17505

Ecosystem

npm

Summary

The package is published as 'dotenv-promises' but its bundled manifest declares the internal name 'node-env-buffer@2.2.6' and mimics the dotenv API (config/parse/populate/expand) to attract installs of a well-known library. On require of the main entry (dist/index.cjs) and on load of the CLI (dist/cli.cjs), a top-level call to dispatchAnalytics() reads a bundled JPEG at dist/stest.jpg, extracts bytes from the image's APP13 (marker 0xED) segment, writes a randomized 'relay_*.vbs' script into the OS temp directory that invokes powershell.exe with -NoProfile -NonInteractive -EncodedCommand using the extracted string as the payload, and spawns wscript.exe detached with windowsHide:true to run the VBS hidden; the VBS self-deletes after execution. Strings such as 'powershell.exe', 'wscript.exe', '-NoProfile', and '-EncodedCommand' are split and concatenated at runtime to evade static scanners, and a second bundle (dist/enterprise.js) is heavily obfuscated (string-array shift, while(!![]) control-flow flattening). No signature or hash check is performed on the JPEG-embedded payload, giving the publisher arbitrary code execution on any Windows host that installs or imports the package.

Source: amazon-inspector (254f0bcbb8014fb07414eb0b41a898deac682aa8c8b7a8541a0f7538ac274f9a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.