LWA-2026-12328 MAL-2026-16394 ↗ confirmed malware

envparse2@1.0.1

Malicious code in envparse2 (npm)

T1059.007 · JavaScriptT1059.001 · PowerShellT1059.003 · Windows Command ShellT1027 · Obfuscated Files or InformationT1036 · Masquerading

Analysis

envparse2@1.0.1 is a trojanized environment-configuration package. On require() of the main entry or execution of its dot2env bin, it reads a bundled 287KB file dist/stest.jpg (a JPEG polyglot), extracts an embedded base64-encoded PowerShell command from the JPEG APP13 metadata marker, writes a self-deleting VBScript relay_<timestamp><random>.vbs into the OS temp directory, and spawns wscript.exe detached and hidden to execute the encoded PowerShell payload. The VBScript deletes itself after launching. The PowerShell payload is delivered via -EncodedCommand and its contents are hidden inside the image file.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 05:25 PM
analyzed
Sep 22, 2026, 05:27 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.