{"id":"MAL-2026-16394","summary":"Malicious code in envparse2 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (59aed7381a2a7026336f5e79671e05e9313688533ca35e15cf7010a975c2c897)\nOn require() of the package's main entry and on invocation of the `dot2env` CLI, the module reads the bundled `dist/stest.jpg`, parses JPEG markers, and extracts a UTF-8 string from the APP13 (0xED) segment. The extracted string is passed as an argument to `powershell.exe -NoProfile -NonInteractive -EncodedCommand`, launched hidden on Windows via a VBS relay dropped to `%TMP%` and invoked through `wscript.exe`. The invocation is assembled from split string fragments (`['power','shell','.exe'].join('')`, `-Encoded`+`Command`, `wscript`+`.exe`) to hide the command from static scanners, and identifiers use a telemetry/analytics cover story (`telemetryFs`, `dispatchAnalytics`, `analyticsEnvelope`, `scanMetricFrame`). Execution is triggered unconditionally by a top-level `const {dispatchAnalytics:Re}=T(); Re();` in `dist/index.cjs`. The bundle also embeds a `package.json` fragment declaring `name: 'node-env-buffer', version: '2.2.6'` while the tarball is published as `envparse2@1.0.1`, indicating a renamed republish under a dotenv-style cover identity. The 287 KB JPEG has no legitimate role in a dotenv-style library; it is a container for the executable payload.\n\n## Source: ghsa-malware (438952ae1e11ed7118f698ec2f5a31caa0af6dd843115a02ba9515a7fc5c21ff)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n","aliases":["GHSA-q747-c2cv-gfhj"],"modified":"2026-09-22T22:30:05.632069093Z","published":"2026-09-22T18:22:20Z","database_specific":{"malicious-packages-origins":[{"ranges":[{"events":[{"introduced":"0"}],"type":"SEMVER"}],"sha256":"438952ae1e11ed7118f698ec2f5a31caa0af6dd843115a02ba9515a7fc5c21ff","source":"ghsa-malware","id":"GHSA-q747-c2cv-gfhj","import_time":"2026-09-22T18:31:21.180571907Z","modified_time":"2026-09-22T18:22:21Z"},{"sha256":"59aed7381a2a7026336f5e79671e05e9313688533ca35e15cf7010a975c2c897","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-020300","import_time":"2026-09-22T22:16:10.43459301Z","modified_time":"2026-09-22T21:49:27Z"}]},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q747-c2cv-gfhj"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/envparse2/v/1.0.1"}],"affected":[{"package":{"name":"envparse2","ecosystem":"npm","purl":"pkg:npm/envparse2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["1.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/envparse2/MAL-2026-16394.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"97fa0d7666e80c68a3cd4f3326dc31bd9203619d6bbae7449efe62de15c4e815","tlsh":"4262f784b3dcb03617eb62e190ab4407e9f5da95408c1418f294e4bb35e46db42fbf79","path":"dist/index.cjs"},{"path":"dist/decode.js","sha256":"f1af48cff9984a5d522d86b82f81dae9deb7d9cf42f12c68253a43acea100d22","tlsh":"03516242adb2a10a076397b787c740282375fd03b404d894b85cc7415faa79e467befd"},{"sha256":"8556eeca50285aea12dfdcbc4ebcee110d916ef81ddde2e338dcf78bda2028cf","tlsh":"d792d74473cdb47a17e621d070ab500beaf2cb60459c1504f2dcb07627f4a9a96ebfb9","path":"dist/cli.cjs"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}