LWA-2026-4250 MAL-2026-5264 ↗ confirmed malware

node-env-resolver-dotenvx@1.0.1

Malicious code in node-env-resolver-dotenvx (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1195.002 · Compromise Software Supply Chain

Analysis

node-env-resolver-dotenvx@1.0.1 carries a ~4.5MB obfuscated eval payload (Caesar-cipher ROT decoder wrapped in eval) in the package-root index.js. Activation is via a binding.gyp whose sources field contains the GYP command substitution '<!(node index.js > /dev/null 2>&1 && echo stub.c)', executing the payload during npm install through node-gyp configure. The legitimate dotenvx/keychain resolver code in dist/ is intact, but a worm payload was injected at the package root; the publisher deprecated this version as a compromised supply-chain build.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 11:55 AM
analyzed
Jun 11, 2026, 11:57 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.