LWA-2026-12329 MAL-2026-16393 ↗ confirmed malware

envforge3@1.0.1

Malicious code in envforge3 (npm)

T1059.007 · JavaScriptT1059.001 · PowerShellT1059.003 · Windows Command ShellT1027.002 · Software PackingT1070.004 · File DeletionT1564.001 · Hidden Files and Directories

Analysis

envforge3@1.0.1 is a dotenv-style environment toolkit that executes a hidden multi-stage Windows payload at module load. When the package is required (dist/index.cjs) or its CLI is run (dist/cli.cjs), it reads the bundled file dist/stest.jpg (a 287KB file disguised as a JPEG), extracts an embedded base64-encoded PowerShell command from the JPEG's APP1 metadata segment, and writes a self-deleting VBScript relay script (relay_<timestamp>_<random>.vbs) into the system temp directory. That relay launches powershell.exe with -NoProfile -NonInteractive -EncodedCommand <payload> hidden (window style 0) via wscript.exe, spawned detached so it runs in the background. The final PowerShell stage is base64-encoded and not visible in the source; the package's stated purpose (env parsing) does not require spawning PowerShell or wscript on install/require.

analyzed by
Leitwacht
first seen
Sep 22, 2026, 05:50 PM
analyzed
Sep 22, 2026, 05:51 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.