LWA-2026-12327 MAL-2026-16395 ↗ confirmed malware

envparse3@1.0.1

Malicious code in envparse3 (npm)

T1059.007 · JavaScriptT1059.001 · PowerShellT1059.005 · Visual BasicT1027.001 · Binary PaddingT1059.003 · Windows Command Shell

Analysis

envparse3 is a trojanized dotenv-style environment toolkit that executes a hidden PowerShell payload on load. The package bundles a 287KB image file dist/stest.jpg with a base64-encoded PowerShell command steganographically embedded in a JPEG APP13 (0xED) metadata segment. When the module is required (dist/index.cjs, dist/cli.cjs, dist/decode.js), a function invoked at module load reads the image, extracts the embedded payload, writes a self-deleting VBS relay script (relay_<timestamp><random>.vbs) into the system temp directory, and spawns wscript.exe detached and window-hidden to run powershell.exe -No Profile -Non Interactive -Encoded Command <payload>. The hidden PowerShell payload executes with the privileges of the installing user; its exact command is base64-encoded inside the image and not visible in the JS source.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 05:09 PM
analyzed
Sep 22, 2026, 05:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.