{"id":"MAL-2026-13741","summary":"Malicious code in safe-local-env-loader (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (79536d7a1e4238fcad87abef5becbb3233148c071cae3c095798417a012896f8)\nsafe-local-env-loader impersonates the legitimate `dotenv` package: its description, repository, homepage, and lib/main.js are copied from motdotla/dotenv, with a single appended `require(\"./tui-options\")` in lib/main.js that activates a hidden agent on module load. On require(), lib/tui-options.js captures full desktop screenshots on Windows and macOS every 3 seconds and POSTs them, together with hostname, platform, and resolution metadata, to a hardcoded bare-IP C2 at http://192.99.204.157:5000/upload. The same module polls http://192.99.204.157:5000/get_buffer every second and replays the returned mouse coordinates and keyboard keys against the installer's desktop via @nut-tree-fork/nut-js (mouse.setPosition/mouse.click and keyboard.pressKey), giving the remote operator interactive control of the host. On Windows, at load time the module writes %APPDATA%\\ScreenCaptureClient\\launch-screen-client.vbs and adds an HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run entry named ScreenCaptureClient so the same agent auto-starts on every user logon. Any installer that requires this package is subjected to screen-content exfiltration, remote input injection, and persistent execution across reboots.\n","modified":"2026-08-11T15:32:27.778240045Z","published":"2026-08-11T15:14:17Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-017354","import_time":"2026-08-11T15:26:47.817900491Z","modified_time":"2026-08-11T15:14:17Z","sha256":"79536d7a1e4238fcad87abef5becbb3233148c071cae3c095798417a012896f8"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/safe-local-env-loader/v/1.0.0"}],"affected":[{"package":{"name":"safe-local-env-loader","ecosystem":"npm","purl":"pkg:npm/safe-local-env-loader"},"versions":["1.0.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"safe-local-env-loader-1.0.0.tgz","hashes":{"sha512_sri":"sha512-5Kxsi6XuQIRgG0nqpk15w3xNuN0JcnUFrCcLWyBlHy4Dk0OK2UBj4D70wEhTWdAQXXsDrAHtqYdbpNqid6s9Ig==","sha1":"75b63b06e287d37cb22e997fd91363c6e10042bb"}}],"evidence_files":[{"tlsh":"6cf193cd583754208b72bba7daa7450ff63693173401c289babc82942f73558c722edc","path":"lib/tui-options.js","sha256":"f44ad69f037cdea4ee893ca74326f0e574c19cf795264dce5414a510c21ba394"},{"path":"lib/main.js","sha256":"c956a80948f211ad6f104ec7432e960766b8f9e1f137e8dd8f9b181313b38a21","tlsh":"15327204a9f9761107c3b2d2954f5009a9bac227361c9f907a8cb3d86f49e78c5e37dd"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/safe-local-env-loader/MAL-2026-13741.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}