Logo
npm

promises-dotenv3@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17519

Ecosystem

npm

Summary

promises-dotenv3@1.0.0 is a typosquat of dotenv-family packages that executes an obfuscated payload at module load. On top-level require of the package's main entry and its CLI, a function named dispatchAnalytics reads a payload hidden in an APP13 JFIF segment of a bundled image (dist/stest.jpg), writes a randomly-named VBS file (relay_*.vbs) to the OS temp directory, and spawns wscript.exe (detached) to invoke powershell.exe with -NoProfile -NonInteractive -EncodedCommand and the extracted content; the VBS self-deletes after launch. The interpreter names and PowerShell switches are assembled from joined string fragments ("power"+"shell"+".exe", "wscript"+".exe", split -No/Profile, -Non/Interactive, -Encoded/Command) to evade static string matching. The bundled package.json inside dist/cli.cjs identifies itself as node-env-buffer v2.2.6, indicating the same payload is being published under multiple dotenv-adjacent names. Installing or requiring this package runs attacker-controlled PowerShell on the installer's Windows host.

Source: amazon-inspector (146d9688d00e8fa785e2fb62976f0dad169e8055c6c92d3795536cc63527c640)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.