VDB

GCVE-110-OSM-2026-12674

GCVE-110-OSM-2026-12674
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published September 28, 2026
Package `dotenv-native` typosquats the popular `dotenv` family (bundled internal manifest name `node-env-buffer`) and executes an attacker-controlled payload on module load. On require, `dist/index.cjs` and the `dot2env` CLI entry `dist/cli.cjs` invoke a `dispatchAnalytics` routine that opens the bundled `dist/stest.jpg`, scans JPEG segments for an APP1/EXIF (0xFFED) marker, extracts the marker contents as a UTF-8 string, writes a `relay_*.vbs` file to a temp directory, and spawns `wscript.exe` detached with `windowsHide:true` to launch `powershell.exe -EncodedCommand <EXIF-derived base64>`. The strings `powershell`, `shell`, `.exe`, `wscript.exe`, and `-EncodedCommand` are split into arrays and joined at runtime to evade static matching. A second artifact `dist/decode.js` is an obfuscator.io-style bundle that base64-decodes an inline blob, RC4-decrypts it with a hardcoded key, base64-decodes again, and passes the result to `new Function(require, module, __filename, __dirname,...)` — a decode-and-eval RCE primitive shipped alongside the main dropper. Both the library entry and the CLI entry carry the loader, so consumption as a dependency or invocation of the `dot2env` bin runs the payload on Windows hosts. ENTRY dist/cli.cjs (bin: ./dist/cli.cjs) DESTINATION - 2 exfil (custom-c2) (values recorded in verified_iocs) EXFIL - System Information Collection in dist/cli.cjs: "process.platform" OBFUSCATION - Obfuscation: augmented proxied array function replacements in dist/decode.js - Base64 Encoded Payload in dist/decode.js: "'GyfDqlLDsk5dVGzDpMOIw60bQwfCoMOWFAkFw7TDi8OiZBHCo8OPwpLDsm/Ch8Kyw6fCkcK4SGfDo1x..." - Obfuscation (osm-deobfuscator): unknown in dist/decode.js - Strings Extracted from Deobfuscated Code in dist/decode.js - Obfuscation patterns: charCodeChain in dist/cli.cjs - Obfuscation patterns: charCodeChain in dist/index.cjs - recovered 2 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Reconstructed Obfuscated Domain in dist/cli.cjs: "powershell.exe" - Dynamic Code Execution in dist/cli.cjs: "exec(n)" - Shell Command Execution in dist/cli.cjs: "require("child_process")" - Silent Process Execution in dist/cli.cjs: "stdio:"ignore"" - Very New NPM Publisher Account PAYLOAD FILES dist/cli.cjs (+ dist/index.cjs)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowndotenv-nativeall (affected)—

References

advisory
vendor

Browse GCVE Records

3,112 records in the GCVE database · Updated October 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›