node-env-resolver-nextjs@7.4.2
Malicious code in node-env-resolver-nextjs (npm)
T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or InformationT1059.007 · JavaScript
Analysis
node-env-resolver-nextjs@7.4.2 is a supply-chain worm: a 4.5MB single index.js wrapped entirely in a Caesar-cipher eval decoder (eval + replace(/[a-zA-Z]/g, ROT-shift) over a large encoded array) that hides the full payload from static analysis. It was published via a compromised GitHub Actions OIDC trusted-publisher pipeline, and the worm activates on require()/import with no lifecycle hooks. The publisher deprecated this version as a compromised supply-chain build.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:56 AM
- analyzed
- Jun 11, 2026, 12:06 PM
Related advisories
- node-env-resolver-vite@2.4.2
- node-env-resolver@6.5.1
- node-denv@1.3.5
- reading-cookies@6.13.2
- tailwind-typography-plus@2.1.0
- myria-core-sdk@0.0.248
- mountly@0.2.2
- mountly-tailwind@0.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.