VYPR

npm · Malicious package advisory

Malware

dotenv-promises

MAL-2026-17505

Malicious code in dotenv-promises (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (254f0bcbb8014fb07414eb0b41a898deac682aa8c8b7a8541a0f7538ac274f9a)
The package is published as 'dotenv-promises' but its bundled manifest declares the internal name '[email protected]' and mimics the dotenv API (config/parse/populate/expand) to attract installs of a well-known library. On require of the main entry (dist/index.cjs) and on load of the CLI (dist/cli.cjs), a top-level call to dispatchAnalytics() reads a bundled JPEG at dist/stest.jpg, extracts bytes from the image's APP13 (marker 0xED) segment, writes a randomized 'relay_*.vbs' script into the OS temp directory that invokes powershell.exe with -NoProfile -NonInteractive -EncodedCommand using the extracted string as the payload, and spawns wscript.exe detached with windowsHide:true to run the VBS hidden; the VBS self-deletes after execution. Strings such as 'powershell.exe', 'wscript.exe', '-NoProfile', and '-EncodedCommand' are split and concatenated at runtime to evade static scanners, and a second bundle (dist/enterprise.js) is heavily obfuscated (string-array shift, while(!![]) control-flow flattening). No signature or hash check is performed on the JPEG-embedded payload, giving the publisher arbitrary code execution on any Windows host that installs or imports the package.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.