MAL-2026-17304

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dotenv-precheck/MAL-2026-17304.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17304
Published
2026-09-30T01:26:29Z
Modified
2026-09-30T01:45:10Z
Summary
Malicious code in dotenv-precheck (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (446a8483dbc9e696506f44c6777b7c086b1b919b2585b5e5c99ca5f6e2e19a8e)

dotenv-precheck@1.0.0 is a credential-stealing package disguised as a dotenv preflight utility. package.json wires index.js as a postinstall script, so it runs automatically on npm install. index.js is heavily obfuscated (obfuscator.io-style hex identifiers, a rotated string array with debugger/toString self-defense, and base64-decoded literals) to hide its runtime strings, which reconstruct at runtime to an api.telegram.org bot endpoint together with a hardcoded bot token and chat ID. On execution the script recursively walks the installer's home directory, including Desktop, Documents, and Downloads, reads text files up to 2MB, and extracts values matching wallet and secret patterns: environment-style entries whose names contain KEY, SECRET, TOKEN, PASSWORD, SEED, MNEMONIC, or WALLET; 0x-prefixed 64-hex Ethereum private keys; Base58 WIF keys; 64-integer Solana key arrays; and BIP-39 mnemonic phrases validated against the BIP-39 word list and SHA-256 checksum. Collected material is uploaded to the attacker's Telegram bot via a sendDocument multipart request to api.telegram.org. No functionality corresponding to the package's stated dotenv-preflight purpose is present.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020781",
            "import_time":  "2026-09-30T01:36:51.094689353Z",
            "modified_time":  "2026-09-30T01:26:38Z",
            "sha256":  "35af933c31e666f3477cb0235667345c54756cb7d84b0f9391f4efbd7948fc7b",
            "source":  "amazon-inspector",
            "versions":  [
                "1.1.1"
            ]
        },
        {
            "id":  "IN-MAL-2026-020780",
            "import_time":  "2026-09-30T01:36:51.014019094Z",
            "modified_time":  "2026-09-30T01:26:29Z",
            "sha256":  "446a8483dbc9e696506f44c6777b7c086b1b919b2585b5e5c99ca5f6e2e19a8e",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020782",
            "import_time":  "2026-09-30T01:36:51.189108739Z",
            "modified_time":  "2026-09-30T01:26:48Z",
            "sha256":  "c1c5b7562cf0887a1f863686169e3a87e15ff324ef2e962028bd4c304893a7a4",
            "source":  "amazon-inspector",
            "versions":  [
                "1.1.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / dotenv-precheck

Package

Name
dotenv-precheck
View open source insights on deps.dev
Purl
pkg:npm/dotenv-precheck

Affected ranges

Affected versions

1.*
1.0.0
1.1.0
1.1.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "d309a636d30fc5bce05090b91d212c9da4e438fc0abcb544ed7dd5a9672abc70",
            "tlsh":  "f2f2e9193bc4a905270f2d3ff51b30f8c69b14ea39840ec9e324f88426a665ab7ddd75"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "dotenv-precheck-1.1.1.tgz",
            "hashes":  {
                "sha1":  "1cd82cd572dc29f25b3011d4768927705cc89267",
                "sha512_sri":  "sha512-yeXpZKhwFamy+71N0QDET0oilFNDtZJiLH7oNL6RB5eH6Zn4z2xj3WQGqafRTDUHvuIqVzvJMHJN00I+PLEN9w=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dotenv-precheck/MAL-2026-17304.json"