dotenv-pack@2.3.5
Malicious code in dotenv-pack (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Combosquat of "dotenv" (versions 2.3.5, 2.3.7, 2.3.10). index.js spawns a detached child running lib/initializeCaller.js, an IIFE that exfiltrates the full process environment ({ ...process.env }, including NPM_TOKEN, GITHUB_TOKEN, etc.) via axios POST to a base64-decoded C2 (ipcheck-hashed[.]vercel[.]app), then executes the server response via new Function("require", response.data) for full remote code execution. Uses the fake author "Robert King" and a jsonspack[.]com URL.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 04:48 PM
- analyzed
- Jun 1, 2026, 04:51 PM
- weekly installs
- 221
Related advisories
- dotenv-pack@2.3.7 same package
- dotenv-pack@2.3.10 same package
- @catamania/front-components@1.0.2
- @convera/ui-shared@0.0.2
- @convera/ui-shared@0.0.3
- msc-terminal@3.2.0
- @asavie/i18n@99.0.3
- forge-jsxy@1.0.91
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.