-= Per source details. Do not edit below this line.=-
dotenv-precheck@1.0.0 is a credential-stealing package disguised as a dotenv preflight utility. package.json wires index.js as a postinstall script, so it runs automatically on npm install. index.js is heavily obfuscated (obfuscator.io-style hex identifiers, a rotated string array with debugger/toString self-defense, and base64-decoded literals) to hide its runtime strings, which reconstruct at runtime to an api.telegram.org bot endpoint together with a hardcoded bot token and chat ID. On execution the script recursively walks the installer's home directory, including Desktop, Documents, and Downloads, reads text files up to 2MB, and extracts values matching wallet and secret patterns: environment-style entries whose names contain KEY, SECRET, TOKEN, PASSWORD, SEED, MNEMONIC, or WALLET; 0x-prefixed 64-hex Ethereum private keys; Base58 WIF keys; 64-integer Solana key arrays; and BIP-39 mnemonic phrases validated against the BIP-39 word list and SHA-256 checksum. Collected material is uploaded to the attacker's Telegram bot via a sendDocument multipart request to api.telegram.org. No functionality corresponding to the package's stated dotenv-preflight purpose is present.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020781",
"import_time": "2026-09-30T01:36:51.094689353Z",
"modified_time": "2026-09-30T01:26:38Z",
"sha256": "35af933c31e666f3477cb0235667345c54756cb7d84b0f9391f4efbd7948fc7b",
"source": "amazon-inspector",
"versions": [
"1.1.1"
]
},
{
"id": "IN-MAL-2026-020780",
"import_time": "2026-09-30T01:36:51.014019094Z",
"modified_time": "2026-09-30T01:26:29Z",
"sha256": "446a8483dbc9e696506f44c6777b7c086b1b919b2585b5e5c99ca5f6e2e19a8e",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
},
{
"id": "IN-MAL-2026-020782",
"import_time": "2026-09-30T01:36:51.189108739Z",
"modified_time": "2026-09-30T01:26:48Z",
"sha256": "c1c5b7562cf0887a1f863686169e3a87e15ff324ef2e962028bd4c304893a7a4",
"source": "amazon-inspector",
"versions": [
"1.1.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "d309a636d30fc5bce05090b91d212c9da4e438fc0abcb544ed7dd5a9672abc70",
"tlsh": "f2f2e9193bc4a905270f2d3ff51b30f8c69b14ea39840ec9e324f88426a665ab7ddd75"
}
],
"package_integrity": [
{
"filename": "dotenv-precheck-1.1.1.tgz",
"hashes": {
"sha1": "1cd82cd572dc29f25b3011d4768927705cc89267",
"sha512_sri": "sha512-yeXpZKhwFamy+71N0QDET0oilFNDtZJiLH7oNL6RB5eH6Zn4z2xj3WQGqafRTDUHvuIqVzvJMHJN00I+PLEN9w=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dotenv-precheck/MAL-2026-17304.json"