core-dotenv@1.4.1
Malicious code in core-dotenv (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted Channel
Analysis
core-dotenv@1.4.1 is a combosquat of the dotenv ecosystem. When required, it fetches a payload from hxxps://realase-0626[.]vercel[.]app/api/v1 and executes the response as arbitrary JavaScript code via Node.js vm.runInContext(), giving the remote server full control over the host. The C2 URL is obfuscated in the source as a hex-encoded character array.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 08:23 AM
- analyzed
- Jul 14, 2026, 08:24 AM
Related advisories
- http-ws-listener@1.0.5
- chai-as-verified@7.1.5
- eth-react-redirection@1.0.0
- chain-js-utils@2.1.1
- chain-await-dom@1.3.4
- chai-as-structured@7.0.5
- vite-pwa-config@1.1.1
- chai-as-disarmed@3.2.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.