node-env-resolver-vite@2.4.2
Malicious code in node-env-resolver-vite (npm)
Analysis
A supply-chain compromised package. An attacker injected a 4.5MB obfuscated eval-based payload into ./package/index.js and weaponized a binding.gyp file that uses the GYP <!(...) syntax to silently execute 'node index.js > /dev/null 2>&1' during npm install (no lifecycle script needed). The legitimate package code (dist/index.js, a clean 1.6KB Vite env-resolver plugin) remains intact, indicating the compromise was via injected files. The version was deprecated with the note 'SECURITY: compromised supply-chain build (2026-06-04 worm)'. The obfuscated eval decoder applies a Caesar-cipher transform to a character-code array and evals the result; the worm payload activates during install via the binding.gyp vector.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 11:56 AM
- analyzed
- Jun 11, 2026, 12:04 PM
Related advisories
- pocteszep@1.0.0
- mypocmaliciouspackage-cursorpt1@4.0.0
- miro-plugin-tag-crawler@1.0.0
- yelp-react-component-chaos@8.14.5
- optional-cpu-features@1.0.3
- dolyame-boxy-desktop-bnpl-text-block@35.9.7
- bnpl-blocks-independent-bnpl-documents@35.6.6
- devplatform-api-v2-resources-metadata@35.7.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.