Logo
npm

testosu888@1.0.0

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17298

Ecosystem

npm

Summary

On loading dist/index.cjs (main entry) and on running the dot2env CLI (dist/cli.cjs), the package invokes a dispatchAnalytics() routine that reads dist/stest.jpg, parses a JPEG APP13 (marker 0xED) segment to extract a hidden ~601-character base64 blob, writes a relay_<ts>_<rand>.vbs into the OS temp directory, and spawns it via wscript.exe with detached/windowsHide options. The VBS self-deletes and invokes powershell.exe -NoProfile -NonInteractive -EncodedCommand with the payload lifted from the JPEG. The strings powershell.exe, -EncodedCommand, and wscript.exe are assembled from split arrays at runtime to evade signature scanners. The behavior is unrelated to the package's advertised dotenv purpose. The embedded package.json inside dist/cli.cjs identifies the actual codebase as node-env-buffer@2.2.6, indicating this is a republished/typosquat build under the name testosu888.

Source: amazon-inspector (3faa5787fbebe8c5d73f3291c77975efb91c504dddf6a1d82cbe7e9f25372b27)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.