{"id":"MAL-2026-17231","summary":"Malicious code in dotenv-native (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4369c7fa886fc7d315922759932056664863d71157bcdece943fa53339586f03)\nPackage `dotenv-native` typosquats the popular `dotenv` family (bundled internal manifest name `node-env-buffer`) and executes an attacker-controlled payload on module load. On require, `dist/index.cjs` and the `dot2env` CLI entry `dist/cli.cjs` invoke a `dispatchAnalytics` routine that opens the bundled `dist/stest.jpg`, scans JPEG segments for an APP1/EXIF (0xFFED) marker, extracts the marker contents as a UTF-8 string, writes a `relay_*.vbs` file to a temp directory, and spawns `wscript.exe` detached with `windowsHide:true` to launch `powershell.exe -EncodedCommand \u003cEXIF-derived base64\u003e`. The strings `powershell`, `shell`, `.exe`, `wscript.exe`, and `-EncodedCommand` are split into arrays and joined at runtime to evade static matching. A second artifact `dist/decode.js` is an obfuscator.io-style bundle that base64-decodes an inline blob, RC4-decrypts it with a hardcoded key, base64-decodes again, and passes the result to `new Function(require, module, __filename, __dirname,...)` — a decode-and-eval RCE primitive shipped alongside the main dropper. Both the library entry and the CLI entry carry the loader, so consumption as a dependency or invocation of the `dot2env` bin runs the payload on Windows hosts.\n","modified":"2026-09-28T22:30:05.663983018Z","published":"2026-09-28T22:04:24Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-020614","import_time":"2026-09-28T22:18:22.840272015Z","modified_time":"2026-09-28T22:04:24Z","sha256":"4369c7fa886fc7d315922759932056664863d71157bcdece943fa53339586f03"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dotenv-native/v/1.0.1"}],"affected":[{"package":{"name":"dotenv-native","ecosystem":"npm","purl":"pkg:npm/dotenv-native"},"versions":["1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"dotenv-native-1.0.1.tgz","hashes":{"sha512_sri":"sha512-dVNgZVtILqMflyHzqApb1jt74FEFOmMdAVtlhyqKPSqvrpHDiSS4ozJB4opbx9JPr1nquiZKrKHyjHNCBTjytA==","sha1":"b0285121efdc934555ce6ad3c26065dc6fc92daa"}}],"evidence_files":[{"sha256":"97fa0d7666e80c68a3cd4f3326dc31bd9203619d6bbae7449efe62de15c4e815","tlsh":"4262f784b3dcb03617eb62e190ab4407e9f5da95408c1418f294e4bb35e46db42fbf79","path":"dist/index.cjs"},{"path":"dist/cli.cjs","sha256":"8556eeca50285aea12dfdcbc4ebcee110d916ef81ddde2e338dcf78bda2028cf","tlsh":"d792d74473cdb47a17e621d070ab500beaf2cb60459c1504f2dcb07627f4a9a96ebfb9"},{"path":"dist/decode.js","sha256":"5dff7ab1aa10ec7fa03079c54b536d8fb54dcf45cf05b3079d0fd0ad850ef35b","tlsh":"f9628d5cfe0a309bdebc03d35bd4139a6afdc0485996241d316b11c33a56a962f93eac"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dotenv-native/MAL-2026-17231.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}