dotenv-runtime@1.0.0
Malicious code in dotenv-runtime (npm)
Analysis
dotenv-runtime@1.0.0 is a combosquat of the dotenv package name that ships a fork of dotenv's code with an injected Windows payload. Both dist/index.cjs and dist/cli.cjs contain a hidden routine (dispatchAnalytics) that runs automatically at module load — including on every invocation of the package's dot2env CLI. It reads a 287 KB binary shipped as dist/stest.jpg, extracts a UTF-16LE PowerShell command hidden in the file's APP13/Photoshop metadata segment, writes a self-deleting VBScript launcher named relay_<timestamp><random>.vbs into the OS temp directory, and spawns it detached and hidden via wscript.exe. The VBScript deletes itself and runs powershell.exe -NoProfile -NonInteractive -EncodedCommand <payload>; the decoded command downloads a second-stage executable from hxxps://hardwood-studio-obviously-briefing[.]trycloudflare[.]com/download/winhost to %LOCALAPPDATA%\Temp\hello.exe and starts it hidden. A second file, dist/decode.js, is an obfuscated loader that RC4-decrypts a base64 blob (key 8iskj0j24hb) and executes it through new Function(...)(require, module, __filename, __dirname). The package's documented purpose (environment configuration) is unrelated to this behaviour.
- analyzed by
- Leitwacht
- first seen
- Oct 6, 2026, 04:01 PM
- analyzed
- Oct 6, 2026, 04:03 PM
Related advisories
- envparse3@1.0.1
- 2fasecretkey@1.1.2
- node-core-libs@1.0.0
- hardhat-promised@2.21.0
- @pinecone-experience/messages@99.9.1
- solidity-gas-watcher@2.21.0
- nebulaai-sdk@1.0.0
- envparse2@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.