{"id":"MAL-2026-17504","summary":"Malicious code in dotenv-async (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (51d22963a1f1fabe3a8b3f54efcb5053761d385486093200765745297ac2bd16)\nThe package impersonates the dotenv API but on module load (and again when the bundled CLI runs) invokes a function named dispatchAnalytics in dist/index.cjs that extracts a payload from the APP14 (0xFFED) marker of dist/stest.jpg. The extracted UTF-16LE base64 string is assembled into a VBS file (relay_\u003ctime\u003e\u003crand\u003e.vbs) in the OS temp directory that invokes powershell.exe with -NoProfile -NonInteractive -EncodedCommand, spawned via wscript.exe in detached, windowsHide mode. The decoded PowerShell downloads a second-stage Windows executable from hardwood-studio-obviously-briefing.trycloudflare.com/download/winhost and executes it, giving arbitrary code execution on Windows installers. String-splitting of powershell/wscript and argument tokens is used to evade static matching. A second obfuscated execution vehicle is shipped in dist/enterprise.js: a hex-named obfuscator.io-style loader that RC4-decrypts a base64 blob and executes it via new Function(require, module, __filename, __dirname, \u003cdecoded\u003e); this file is not referenced by index.cjs in the current build but is a dormant secondary stage in the tarball. Identity inconsistencies corroborate intent: cli.cjs bundles an inner package.json declaring name node-env-buffer version 2.2.6 while the outer manifest is dotenv-async 1.0.0, and the README points at the unrelated motdotla/dotenv project.\n","modified":"2026-10-04T23:45:17.914871741Z","published":"2026-10-04T23:29:08Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-04T23:40:47.860950215Z","modified_time":"2026-10-04T23:29:08Z","sha256":"51d22963a1f1fabe3a8b3f54efcb5053761d385486093200765745297ac2bd16","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020978"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dotenv-async/v/1.0.0"}],"affected":[{"package":{"name":"dotenv-async","ecosystem":"npm","purl":"pkg:npm/dotenv-async"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/dotenv-async/MAL-2026-17504.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"97fa0d7666e80c68a3cd4f3326dc31bd9203619d6bbae7449efe62de15c4e815","tlsh":"4262f784b3dcb03617eb62e190ab4407e9f5da95408c1418f294e4bb35e46db42fbf79","path":"dist/index.cjs"},{"path":"dist/enterprise.js","sha256":"c603a9d04709f277ae7057150019db50d4d9721b87bad0da46013b92fe8e4723","tlsh":"d0425d48fe4e2087cffa93e31f611a54627dc288719e2068627a03d13a35a9295d7dfc"},{"sha256":"8556eeca50285aea12dfdcbc4ebcee110d916ef81ddde2e338dcf78bda2028cf","tlsh":"d792d74473cdb47a17e621d070ab500beaf2cb60459c1504f2dcb07627f4a9a96ebfb9","path":"dist/cli.cjs"}],"package_integrity":[{"filename":"dotenv-async-1.0.0.tgz","hashes":{"sha512_sri":"sha512-GepLJaTZvi8ZueAx69Y81bkBb9EtTLy83QpJVrb/vHnvEGU+ctg/54xYn25oWHZMcjKRri61w6IMXduNa3HDRg==","sha1":"331578bdeea70972602bd1ef7884c7f69c18a362"}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}