peptideenv@16.6.6
Malicious code in peptideenv (npm)
Analysis
peptideenv@16.6.6 is a combosquat of the popular dotenv package (same description, same repo URL fraudulently claimed, version 16.6.6 matching dotenv's version series). The publisher (richswift225) previously published the confirmed-malicious js-unimode. The main entry point is heavily obfuscated with javascript-obfuscator and contains a multi-stage C2 backdoor that fires immediately on require(): it contacts a C2 server on port 1244 (reconstructed from obfuscated base64), transmits a system fingerprint (hostname, platform, username, node version) via POST with fields ts/type/hid/ss/cc, then downloads and executes secondary JS payloads saved to ~/.vscode/*.fjs, followed by downloading npm packages and running them via detached node/nohup processes. The attack retries up to 3 times at ~10-minute intervals. The package also contains a copy of dotenv's legitimate parse() function at the bottom of the file to disguise its behavior.
- analyzed by
- Leitwacht
- first seen
- Jun 12, 2026, 06:00 AM
- analyzed
- Jun 12, 2026, 06:01 AM
Related advisories
- packageuwu@1.0.1
- paasprint-sdk@9.9.9
- coral-wraith@1.0.4
- worker-build@9.0.1
- index-ulid@3.0.2
- npm-scanner@1.0.0
- npmjs-doc-builder@1.0.1
- npm-bs58.js@2.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.