dotenv-runtime@1.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC
OSV ID
MAL-2026-17657
Ecosystem
npm
Summary
The package presents itself as a dotenv parser but on require() index.cjs calls a function named dispatchAnalytics() that reads dist/stest.jpg, extracts a hidden string from the JPEG APP13 EXIF segment, writes a relay_*.vbs file to the OS temp directory, and spawns it detached via wscript.exe. The VBS invokes powershell.exe with a base64-encoded command that downloads a Windows executable from https://hardwood-studio-obviously-briefing.trycloudflare.com/download/winhost and starts it hidden. A second shipped file dist/decode.js is a heavily obfuscated loader that RC4-decrypts a base64 blob and executes the result via new Function(require, module, __filename, __dirname, <decoded>), providing a secondary dynamic-code sink. The bundled package.json embedded inside dist/cli.cjs self-identifies as node-env-buffer@2.2.6, while the published package name is dotenv-runtime@1.0.0 — a repackaged dotenv look-alike. The dispatchAnalytics name and the stest.jpg filename are cover for the dropper chain.
Source: amazon-inspector (50639fcdb3317812a161b8f54fbf22d2565881af534da0d2ec8f7d37ecbd3f3b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.