{"id":"MAL-2026-17519","summary":"Malicious code in promises-dotenv3 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (146d9688d00e8fa785e2fb62976f0dad169e8055c6c92d3795536cc63527c640)\npromises-dotenv3@1.0.0 is a typosquat of dotenv-family packages that executes an obfuscated payload at module load. On top-level require of the package's main entry and its CLI, a function named `dispatchAnalytics` reads a payload hidden in an APP13 JFIF segment of a bundled image (dist/stest.jpg), writes a randomly-named VBS file (relay_*.vbs) to the OS temp directory, and spawns wscript.exe (detached) to invoke powershell.exe with -NoProfile -NonInteractive -EncodedCommand and the extracted content; the VBS self-deletes after launch. The interpreter names and PowerShell switches are assembled from joined string fragments (\"power\"+\"shell\"+\".exe\", \"wscript\"+\".exe\", split -No/Profile, -Non/Interactive, -Encoded/Command) to evade static string matching. The bundled package.json inside dist/cli.cjs identifies itself as `node-env-buffer` v2.2.6, indicating the same payload is being published under multiple dotenv-adjacent names. Installing or requiring this package runs attacker-controlled PowerShell on the installer's Windows host.\n","modified":"2026-10-04T23:45:20.816344170Z","published":"2026-10-04T23:26:12Z","database_specific":{"malicious-packages-origins":[{"sha256":"146d9688d00e8fa785e2fb62976f0dad169e8055c6c92d3795536cc63527c640","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020959","import_time":"2026-10-04T23:40:45.981048735Z","modified_time":"2026-10-04T23:26:12Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/promises-dotenv3/v/1.0.0"}],"affected":[{"package":{"name":"promises-dotenv3","ecosystem":"npm","purl":"pkg:npm/promises-dotenv3"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/promises-dotenv3/MAL-2026-17519.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"dist/index.cjs","sha256":"97fa0d7666e80c68a3cd4f3326dc31bd9203619d6bbae7449efe62de15c4e815","tlsh":"4262f784b3dcb03617eb62e190ab4407e9f5da95408c1418f294e4bb35e46db42fbf79"},{"sha256":"8556eeca50285aea12dfdcbc4ebcee110d916ef81ddde2e338dcf78bda2028cf","tlsh":"d792d74473cdb47a17e621d070ab500beaf2cb60459c1504f2dcb07627f4a9a96ebfb9","path":"dist/cli.cjs"}],"package_integrity":[{"filename":"promises-dotenv3-1.0.0.tgz","hashes":{"sha1":"7e1685fab16c44df641af78e4b581044136e7fea","sha512_sri":"sha512-E5zUfEgoiDMxH5YzEFaTyMp1FkYh5DBcILzGtFMPvhSTyc8wWq0eYVd3EVFGKQRCNhefz4IoGpkr7vxyvkjfJA=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}