dotenv-pack@2.3.7
Malicious code in dotenv-pack (npm)
T1195.002 · Compromise Software Supply Chain
Analysis
Combosquat of "dotenv" (versions 2.3.5, 2.3.7, 2.3.10). index.js spawns a detached child running lib/initializeCaller.js, an IIFE that exfiltrates the full process environment ({ ...process.env }, including NPM_TOKEN, GITHUB_TOKEN, etc.) via axios POST to a base64-decoded C2 (ipcheck-hashed[.]vercel[.]app), then executes the server response via new Function("require", response.data) for full remote code execution. Uses the fake author "Robert King" and a jsonspack[.]com URL.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 04:48 PM
- analyzed
- Jun 1, 2026, 04:51 PM
- weekly installs
- 221
Related advisories
- dotenv-pack@2.3.5 same package
- dotenv-pack@2.3.10 same package
- chai-as-init@1.4.6
- jsf-utils@1.3.1
- envfile-sync-cli@1.0.2
- chai-utils-test@4.5.1
- chai-utils-test@4.5.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.