MAL-2026-17231
Malicious code in dotenv-native (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (4369c7fa886fc7d315922759932056664863d71157bcdece943fa53339586f03) Package `dotenv-native` typosquats the popular `dotenv` family (bundled internal manifest name `node-env-buffer`) and executes an attacker-controlled payload on module load. On require, `dist/index.cjs` and the `dot2env` CLI entry `dist/cli.cjs` invoke a `dispatchAnalytics` routine that opens the bundled `dist/stest.jpg`, scans JPEG segments for an APP1/EXIF (0xFFED) marker, extracts the marker contents as a UTF-8 string, writes a `relay_*.vbs` file to a temp directory, and spawns `wscript.exe` detached with `windowsHide:true` to launch `powershell.exe -EncodedCommand <EXIF-derived base64>`. The strings `powershell`, `shell`, `.exe`, `wscript.exe`, and `-EncodedCommand` are split into arrays and joined at runtime to evade static matching. A second artifact `dist/decode.js` is an obfuscator.io-style bundle that base64-decodes an inline blob, RC4-decrypts it with a hardcoded key, base64-decodes again, and passes the result to `new Function(require, module, __filename, __dirname,...)` — a decode-and-eval RCE primitive shipped alongside the main dropper. Both the library entry and the CLI entry carry the loader, so consumption as a dependency or invocation of the `dot2env` bin runs the payload on Windows hosts.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for dotenv-native (npm). Pin to a known-safe version or switch to an alternative.