npm · Malicious package advisory
Malwaredotenv-pack
MAL-2026-2900
Malicious code in dotenv-pack (npm)
Details
dotenv-pack is a malicious npm package that when imported downloads a C2 dropper from https://api.npoint[.]io/5b357f718ab4ee355003 and executes it (similar to malware in to chai-await-test). --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (b57650f0341c4520703e30ebd6c256f564519680e225e8dabefcd48b4218dfa1) The package dotenv-pack was found to contain malicious code.