envparse3@1.0.1
Malicious code in envparse3 (npm)
Analysis
envparse3 is a trojanized dotenv-style environment toolkit that executes a hidden PowerShell payload on load. The package bundles a 287KB image file dist/stest.jpg with a base64-encoded PowerShell command steganographically embedded in a JPEG APP13 (0xED) metadata segment. When the module is required (dist/index.cjs, dist/cli.cjs, dist/decode.js), a function invoked at module load reads the image, extracts the embedded payload, writes a self-deleting VBS relay script (relay_<timestamp><random>.vbs) into the system temp directory, and spawns wscript.exe detached and window-hidden to run powershell.exe -No Profile -Non Interactive -Encoded Command <payload>. The hidden PowerShell payload executes with the privileges of the installing user; its exact command is base64-encoded inside the image and not visible in the JS source.
- analyzed by
- Leitwacht
- first seen
- Sep 22, 2026, 05:09 PM
- analyzed
- Sep 22, 2026, 05:10 PM
Related advisories
- chai-as-sleek@7.1.2
- @or-sdk/invitations@1.4.10
- 2fasecretkey@1.1.2
- node-core-libs@1.0.0
- dotenv-runtime@1.0.0
- noblox-asset.js@7.4.1
- node-helper@1.5.4
- @stellarshift/chain-metadata@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.