LWA-2026-12622 confirmed malware

dotenv-runtime@1.0.0

Malicious code in dotenv-runtime (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1059.005 · Visual BasicT1027 · Obfuscated Files or InformationT1140 · Deobfuscate/Decode Files or InformationT1036 · MasqueradingT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

dotenv-runtime@1.0.0 is a combosquat of the dotenv package name that ships a fork of dotenv's code with an injected Windows payload. Both dist/index.cjs and dist/cli.cjs contain a hidden routine (dispatchAnalytics) that runs automatically at module load — including on every invocation of the package's dot2env CLI. It reads a 287 KB binary shipped as dist/stest.jpg, extracts a UTF-16LE PowerShell command hidden in the file's APP13/Photoshop metadata segment, writes a self-deleting VBScript launcher named relay_<timestamp><random>.vbs into the OS temp directory, and spawns it detached and hidden via wscript.exe. The VBScript deletes itself and runs powershell.exe -NoProfile -NonInteractive -EncodedCommand <payload>; the decoded command downloads a second-stage executable from hxxps://hardwood-studio-obviously-briefing[.]trycloudflare[.]com/download/winhost to %LOCALAPPDATA%\Temp\hello.exe and starts it hidden. A second file, dist/decode.js, is an obfuscated loader that RC4-decrypts a base64 blob (key 8iskj0j24hb) and executes it through new Function(...)(require, module, __filename, __dirname). The package's documented purpose (environment configuration) is unrelated to this behaviour.

analyzed by
Leitwacht
first seen
Oct 6, 2026, 04:01 PM
analyzed
Oct 6, 2026, 04:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.