envforge3@1.0.1
Malicious code in envforge3 (npm)
Analysis
envforge3@1.0.1 is a dotenv-style environment toolkit that executes a hidden multi-stage Windows payload at module load. When the package is required (dist/index.cjs) or its CLI is run (dist/cli.cjs), it reads the bundled file dist/stest.jpg (a 287KB file disguised as a JPEG), extracts an embedded base64-encoded PowerShell command from the JPEG's APP1 metadata segment, and writes a self-deleting VBScript relay script (relay_<timestamp>_<random>.vbs) into the system temp directory. That relay launches powershell.exe with -NoProfile -NonInteractive -EncodedCommand <payload> hidden (window style 0) via wscript.exe, spawned detached so it runs in the background. The final PowerShell stage is base64-encoded and not visible in the source; the package's stated purpose (env parsing) does not require spawning PowerShell or wscript on install/require.
- analyzed by
- Leitwacht
- first seen
- Sep 22, 2026, 05:50 PM
- analyzed
- Sep 22, 2026, 05:51 PM
Related advisories
- @or-sdk/library@0.5.8
- @servicetitan/mfe-quick-actions@0.5.53
- @ornikar/rollup-plugin-postcss@2.0.10
- @ornikar/eslint-config-babel-use@13.2.4
- assertion-utils-js@2.4.3
- boardflow@1.1.4
- ui-core-system@1.0.3
- snavbox@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.