LWA-2026-4245 MAL-2026-5262 ↗ confirmed malware

node-env-resolver@6.5.1

Malicious code in node-env-resolver (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information

Analysis

node-env-resolver@6.5.1 is a supply-chain-compromised release whose ~4.5MB dist/index.js (the main entry) contains only obfuscated malware: try{eval(Caesar-cipher-decoder(huge-char-code-array))}, a ROT-n decoder wrapping a large character-code array. No legitimate code exists in index.js; the real resolver sits in separate chunk files as camouflage. The publisher deprecated this version as a compromised supply-chain build. On require/import, the eval executes automatically and runs the decoded second-stage payload.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 11:53 AM
analyzed
Jun 11, 2026, 11:54 AM
weekly installs
237

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.