-= Per source details. Do not edit below this line.=-
Package dotenv-native typosquats the popular dotenv family (bundled internal manifest name node-env-buffer) and executes an attacker-controlled payload on module load. On require, dist/index.cjs and the dot2env CLI entry dist/cli.cjs invoke a dispatchAnalytics routine that opens the bundled dist/stest.jpg, scans JPEG segments for an APP1/EXIF (0xFFED) marker, extracts the marker contents as a UTF-8 string, writes a relay_*.vbs file to a temp directory, and spawns wscript.exe detached with windowsHide:true to launch powershell.exe -EncodedCommand <EXIF-derived base64>. The strings powershell, shell, .exe, wscript.exe, and -EncodedCommand are split into arrays and joined at runtime to evade static matching. A second artifact dist/decode.js is an obfuscator.io-style bundle that base64-decodes an inline blob, RC4-decrypts it with a hardcoded key, base64-decodes again, and passes the result to new Function(require, module, __filename, __dirname,...) — a decode-and-eval RCE primitive shipped alongside the main dropper. Both the library entry and the CLI entry carry the loader, so consumption as a dependency or invocation of the dot2env bin runs the payload on Windows hosts.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020614",
"import_time": "2026-09-28T22:18:22.840272015Z",
"modified_time": "2026-09-28T22:04:24Z",
"sha256": "4369c7fa886fc7d315922759932056664863d71157bcdece943fa53339586f03",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/index.cjs",
"sha256": "97fa0d7666e80c68a3cd4f3326dc31bd9203619d6bbae7449efe62de15c4e815",
"tlsh": "4262f784b3dcb03617eb62e190ab4407e9f5da95408c1418f294e4bb35e46db42fbf79"
},
{
"path": "dist/cli.cjs",
"sha256": "8556eeca50285aea12dfdcbc4ebcee110d916ef81ddde2e338dcf78bda2028cf",
"tlsh": "d792d74473cdb47a17e621d070ab500beaf2cb60459c1504f2dcb07627f4a9a96ebfb9"
},
{
"path": "dist/decode.js",
"sha256": "5dff7ab1aa10ec7fa03079c54b536d8fb54dcf45cf05b3079d0fd0ad850ef35b",
"tlsh": "f9628d5cfe0a309bdebc03d35bd4139a6afdc0485996241d316b11c33a56a962f93eac"
}
],
"package_integrity": [
{
"filename": "dotenv-native-1.0.1.tgz",
"hashes": {
"sha1": "b0285121efdc934555ce6ad3c26065dc6fc92daa",
"sha512_sri": "sha512-dVNgZVtILqMflyHzqApb1jt74FEFOmMdAVtlhyqKPSqvrpHDiSS4ozJB4opbx9JPr1nquiZKrKHyjHNCBTjytA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dotenv-native/MAL-2026-17231.json"