Logo
npm

esm-dotenv@1.0.1

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17305

Ecosystem

npm

Summary

The package advertises itself as a zero-dependency dotenv parser but its main entry dist/index.cjs and CLI bin dist/cli.cjs both invoke dispatchAnalytics() at top-level module load. That function reads dist/stest.jpg, walks the JPEG marker structure to extract the APP13 (0xED) segment as UTF-8, treats those bytes as a base64-encoded PowerShell command, writes a relay_*.vbs wrapper into os.tmpdir(), and spawns wscript.exe detached with windowsHide:true to launch powershell.exe -NoProfile -NonInteractive -EncodedCommand <payload>. The powershell.exe and -EncodedCommand strings are assembled from split-array joins (["power","shell",".exe"].join("")) to evade static keyword scanners, and the payload bytes are hidden inside a JPEG segment rather than in JavaScript source. A second shipped loader, dist/decode.js, is heavily obfuscated (string-array + numeric-id lookup) and reconstructs code via RC4-style XOR of a base64 blob (~8 KB decoded) before executing it through new Function('require','module','__filename','__dirname', <decoded>), providing an additional dynamic-code sink. The dropper fires the moment any Windows host imports the package.

Source: amazon-inspector (55c5c67c48596e011158554f8b5ea57d65a8a8dc3b5f4120d3c9c4d1cf961da2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.