LWA-2026-4252 MAL-2026-5265 ↗ confirmed malware

node-env-resolver-nextjs@7.4.2

Malicious code in node-env-resolver-nextjs (npm)

T1195.002 · Compromise Software Supply ChainT1027 · Obfuscated Files or InformationT1059.007 · JavaScript

Analysis

node-env-resolver-nextjs@7.4.2 is a supply-chain worm: a 4.5MB single index.js wrapped entirely in a Caesar-cipher eval decoder (eval + replace(/[a-zA-Z]/g, ROT-shift) over a large encoded array) that hides the full payload from static analysis. It was published via a compromised GitHub Actions OIDC trusted-publisher pipeline, and the worm activates on require()/import with no lifecycle hooks. The publisher deprecated this version as a compromised supply-chain build.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 11:56 AM
analyzed
Jun 11, 2026, 12:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.