{"id":"MAL-2026-16324","summary":"Malicious code in better-envforge (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1f30026347d1db5e0ade5afe4b81a8569eb6ec0c41d1e1fa79f66dc386a6ea51)\nbetter-envforge@1.0.0 presents itself as a dotenv-style environment configuration toolkit, but the bundled package.json inside dist/cli.cjs identifies the code as node-env-buffer@2.2.6 — a name/purpose mismatch used as a cover story. On require() of the package (main dist/index.cjs) and when the bin `dot2env` CLI is invoked (dist/cli.cjs), a top-level function (dispatchAnalytics) reads dist/stest.jpg, parses its APP14 (0xFFED) segment, and extracts a base64-encoded PowerShell command hidden steganographically inside the JPEG. It then writes a self-deleting VBS relay to os.tmpdir() and launches it via wscript.exe, which in turn runs `powershell.exe -NoProfile -NonInteractive -EncodedCommand \u003cpayload\u003e` detached with windowsHide. Command tokens (`powershell.exe`, `-NoProfile`, `-NonInteractive`, `-EncodedCommand`, `wscript.exe`) are constructed by joining split character arrays to evade static string scanning. Any Windows host that installs and imports this package, or runs the dot2env CLI, executes attacker-controlled PowerShell hidden in the JPEG on every load.\n","modified":"2026-09-21T04:00:05.816916483Z","published":"2026-09-21T03:29:39Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-020223","import_time":"2026-09-21T03:46:37.369703103Z","modified_time":"2026-09-21T03:29:39Z","sha256":"1f30026347d1db5e0ade5afe4b81a8569eb6ec0c41d1e1fa79f66dc386a6ea51","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/better-envforge/v/1.0.0"}],"affected":[{"package":{"name":"better-envforge","ecosystem":"npm","purl":"pkg:npm/better-envforge"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/better-envforge/MAL-2026-16324.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"97fa0d7666e80c68a3cd4f3326dc31bd9203619d6bbae7449efe62de15c4e815","tlsh":"4262f784b3dcb03617eb62e190ab4407e9f5da95408c1418f294e4bb35e46db42fbf79","path":"dist/index.cjs"},{"tlsh":"d792d74473cdb47a17e621d070ab500beaf2cb60459c1504f2dcb07627f4a9a96ebfb9","path":"dist/cli.cjs","sha256":"8556eeca50285aea12dfdcbc4ebcee110d916ef81ddde2e338dcf78bda2028cf"},{"sha256":"f1af48cff9984a5d522d86b82f81dae9deb7d9cf42f12c68253a43acea100d22","tlsh":"03516242adb2a10a076397b787c740282375fd03b404d894b85cc7415faa79e467befd","path":"dist/decode.js"}],"package_integrity":[{"hashes":{"sha1":"22e3ccf88ea5d47aaf0c2517193d8ed2a45ed489","sha512_sri":"sha512-HrebdgYNOctfWIDvBIddENOxHtWLHwpG6T/9wPzMTT3DWpRuu+BdtEM+C0g8AgxW9kwYy9uLQ4KknRGnsALvDg=="},"filename":"better-envforge-1.0.0.tgz"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}