npm · Malicious package advisory
Malwaredotenv-async
GHSA-5gq4-v664-5cwf
Malicious code in dotenv-async (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (51d22963a1f1fabe3a8b3f54efcb5053761d385486093200765745297ac2bd16) The package impersonates the dotenv API but on module load (and again when the bundled CLI runs) invokes a function named dispatchAnalytics in dist/index.cjs that extracts a payload from the APP14 (0xFFED) marker of dist/stest.jpg. The extracted UTF-16LE base64 string is assembled into a VBS file (relay_<time><rand>.vbs) in the OS temp directory that invokes powershell.exe with -NoProfile -NonInteractive -EncodedCommand, spawned via wscript.exe in detached, windowsHide mode. The decoded PowerShell downloads a second-stage Windows executable from hardwood-studio-obviously-briefing.trycloudflare.com/download/winhost and executes it, giving arbitrary code execution on Windows installers. String-splitting of powershell/wscript and argument tokens is used to evade static matching. A second obfuscated execution vehicle is shipped in dist/enterprise.js: a hex-named obfuscator.io-style loader that RC4-decrypts a base64 blob and executes it via new Function(require, module, __filename, __dirname, <decoded>); this file is not referenced by index.cjs in the current build but is a dormant secondary stage in the tarball. Identity inconsistencies corroborate intent: cli.cjs bundles an inner package.json declaring name node-env-buffer version 2.2.6 while the outer manifest is dotenv-async 1.0.0, and the README points at the unrelated motdotla/dotenv project. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/dotenv-async/MAL-2026-17504.json)) **References:** - https://github.com/ossf/malicious-packages/blob/ae1ef40954ea15dd560720d58f647c9880afc699/osv/malicious/npm/dotenv-async/MAL-2026-17504.json - https://www.npmjs.com/package/dotenv-async/v/1.0.0 - https://github.com/advisories/GHSA-5gq4-v664-5cwf
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.