node-env-resolver-dotenvx@1.0.1
Malicious code in node-env-resolver-dotenvx (npm)
T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1195.002 · Compromise Software Supply Chain
Analysis
node-env-resolver-dotenvx@1.0.1 carries a ~4.5MB obfuscated eval payload (Caesar-cipher ROT decoder wrapped in eval) in the package-root index.js. Activation is via a binding.gyp whose sources field contains the GYP command substitution '<!(node index.js > /dev/null 2>&1 && echo stub.c)', executing the payload during npm install through node-gyp configure. The legitimate dotenvx/keychain resolver code in dist/ is intact, but a worm payload was injected at the package root; the publisher deprecated this version as a compromised supply-chain build.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:55 AM
- analyzed
- Jun 11, 2026, 11:57 AM
Related advisories
- nodecheck-health@1.0.0
- nj-logger@1.3.2
- n8n-nodes-pentest-rce@1.0.1
- myria-core-sdk@0.0.248
- motion-lib@2.3.5
- mimecast-web-components@2.0.0
- metrica-node@2.4.5
- metrica-chain@2.4.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.