npm · Malicious package advisory
Malwaredotenv-async
MAL-2026-17504
Malicious code in dotenv-async (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (51d22963a1f1fabe3a8b3f54efcb5053761d385486093200765745297ac2bd16) The package impersonates the dotenv API but on module load (and again when the bundled CLI runs) invokes a function named dispatchAnalytics in dist/index.cjs that extracts a payload from the APP14 (0xFFED) marker of dist/stest.jpg. The extracted UTF-16LE base64 string is assembled into a VBS file (relay_<time><rand>.vbs) in the OS temp directory that invokes powershell.exe with -NoProfile -NonInteractive -EncodedCommand, spawned via wscript.exe in detached, windowsHide mode. The decoded PowerShell downloads a second-stage Windows executable from hardwood-studio-obviously-briefing.trycloudflare.com/download/winhost and executes it, giving arbitrary code execution on Windows installers. String-splitting of powershell/wscript and argument tokens is used to evade static matching. A second obfuscated execution vehicle is shipped in dist/enterprise.js: a hex-named obfuscator.io-style loader that RC4-decrypts a base64 blob and executes it via new Function(require, module, __filename, __dirname, <decoded>); this file is not referenced by index.cjs in the current build but is a dormant secondary stage in the tarball. Identity inconsistencies corroborate intent: cli.cjs bundles an inner package.json declaring name node-env-buffer version 2.2.6 while the outer manifest is dotenv-async 1.0.0, and the README points at the unrelated motdotla/dotenv project.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.