envparse2@1.0.1
Malicious code in envparse2 (npm)
Analysis
envparse2@1.0.1 is a trojanized environment-configuration package. On require() of the main entry or execution of its dot2env bin, it reads a bundled 287KB file dist/stest.jpg (a JPEG polyglot), extracts an embedded base64-encoded PowerShell command from the JPEG APP13 metadata marker, writes a self-deleting VBScript relay_<timestamp><random>.vbs into the OS temp directory, and spawns wscript.exe detached and hidden to execute the encoded PowerShell payload. The VBScript deletes itself after launching. The PowerShell payload is delivered via -EncodedCommand and its contents are hidden inside the image file.
- analyzed by
- Leitwacht
- first seen
- Sep 22, 2026, 05:25 PM
- analyzed
- Sep 22, 2026, 05:27 PM
Related advisories
- @shared-web/assets@9.9.10
- sbironman@1.0.0
- ded-aa-common-ded-aa-common-core@35.1.6
- bnpl-blocks-independent-bnpl-open-api@35.1.2
- bigops-api@35.8.8
- dolyame-ui-loader@35.1.5
- devplatform-spa-plugin-dom-render@35.5.5
- invest-module-cookie@20.8.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.