Logo
npm

stestenv@1.0.1

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17309

Ecosystem

npm

Summary

On require of the package's main entry, dispatchAnalytics() reads a payload hidden in the JPEG APP13 (marker 0xFFED) segment of the bundled dist/stest.jpg, decrypts it with a hardcoded AES-256-CBC key to obtain a UTF-16LE PowerShell command, writes a VBScript to the OS tmpdir, and launches it via wscript.exe to run powershell.exe -NoProfile -NonInteractive -EncodedCommand <payload>. Runtime binary names are string-split ("power"+"shell", "wscript"+".exe") and the process is spawned detached with windowsHide:true and .unref() to evade lexical scanners and hide the window. A companion dist/decode.js confirms the encrypted PowerShell payload format (hardcoded 32-byte key, AES-256-CBC, UTF-16LE, re-base64 for -EncodedCommand). The bundled cli embeds an inlined package.json with a different identity (name:"node-env-buffer", version:"2.2.6") than the published stestenv name, indicating the same dropper is being redistributed under multiple names while presenting a dotenv-style cover story. Installing or importing this package on Windows results in silent execution of attacker-controlled code hidden inside a shipped image asset.

Source: amazon-inspector (ee35b23a60484ee1d468154734cc7cdbc8c7d3cbc81901ab680cb67e46a8c2b6)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.