VYPR

npm · Malicious package advisory

Malware

dotenv-pack

MAL-2026-2900

Malicious code in dotenv-pack (npm)

Details

dotenv-pack is a malicious npm package that when imported downloads a C2 dropper from https://api.npoint[.]io/5b357f718ab4ee355003 and executes it (similar to malware in to chai-await-test).

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b57650f0341c4520703e30ebd6c256f564519680e225e8dabefcd48b4218dfa1)
The package dotenv-pack was found to contain malicious code.