node-env-resolver@6.5.1
Malicious code in node-env-resolver (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information
Analysis
node-env-resolver@6.5.1 is a supply-chain-compromised release whose ~4.5MB dist/index.js (the main entry) contains only obfuscated malware: try{eval(Caesar-cipher-decoder(huge-char-code-array))}, a ROT-n decoder wrapping a large character-code array. No legitimate code exists in index.js; the real resolver sits in separate chunk files as camouflage. The publisher deprecated this version as a compromised supply-chain build. On require/import, the eval executes automatically and runs the decoded second-stage payload.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:53 AM
- analyzed
- Jun 11, 2026, 11:54 AM
- weekly installs
- 237
Related advisories
- node-denv@1.3.5
- reading-cookies@6.13.2
- tailwind-typography-plus@2.1.0
- myria-core-sdk@0.0.248
- mountly@0.2.2
- mountly-tailwind@0.1.3
- postcss-processor-utils@1.0.3
- fastify-addon@5.1.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.