-= Per source details. Do not edit below this line.=-
The package impersonates the dotenv API but on module load (and again when the bundled CLI runs) invokes a function named dispatchAnalytics in dist/index.cjs that extracts a payload from the APP14 (0xFFED) marker of dist/stest.jpg. The extracted UTF-16LE base64 string is assembled into a VBS file (relay_
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020978",
"import_time": "2026-10-04T23:40:47.860950215Z",
"modified_time": "2026-10-04T23:29:08Z",
"sha256": "51d22963a1f1fabe3a8b3f54efcb5053761d385486093200765745297ac2bd16",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/index.cjs",
"sha256": "97fa0d7666e80c68a3cd4f3326dc31bd9203619d6bbae7449efe62de15c4e815",
"tlsh": "4262f784b3dcb03617eb62e190ab4407e9f5da95408c1418f294e4bb35e46db42fbf79"
},
{
"path": "dist/enterprise.js",
"sha256": "c603a9d04709f277ae7057150019db50d4d9721b87bad0da46013b92fe8e4723",
"tlsh": "d0425d48fe4e2087cffa93e31f611a54627dc288719e2068627a03d13a35a9295d7dfc"
},
{
"path": "dist/cli.cjs",
"sha256": "8556eeca50285aea12dfdcbc4ebcee110d916ef81ddde2e338dcf78bda2028cf",
"tlsh": "d792d74473cdb47a17e621d070ab500beaf2cb60459c1504f2dcb07627f4a9a96ebfb9"
}
],
"package_integrity": [
{
"filename": "dotenv-async-1.0.0.tgz",
"hashes": {
"sha1": "331578bdeea70972602bd1ef7884c7f69c18a362",
"sha512_sri": "sha512-GepLJaTZvi8ZueAx69Y81bkBb9EtTLy83QpJVrb/vHnvEGU+ctg/54xYn25oWHZMcjKRri61w6IMXduNa3HDRg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dotenv-async/MAL-2026-17504.json"