VDB
GCVE-110-OSM-2026-12674
GCVE-110-OSM-2026-12674
Advisory PublishedCVSS 9.6/10
Package `dotenv-native` typosquats the popular `dotenv` family (bundled internal manifest name `node-env-buffer`) and executes an attacker-controlled payload on module load. On require, `dist/index.cjs` and the `dot2env` CLI entry `dist/cli.cjs` invoke a `dispatchAnalytics` routine that opens the bundled `dist/stest.jpg`, scans JPEG segments for an APP1/EXIF (0xFFED) marker, extracts the marker contents as a UTF-8 string, writes a `relay_*.vbs` file to a temp directory, and spawns `wscript.exe` detached with `windowsHide:true` to launch `powershell.exe -EncodedCommand <EXIF-derived base64>`. The strings `powershell`, `shell`, `.exe`, `wscript.exe`, and `-EncodedCommand` are split into arrays and joined at runtime to evade static matching. A second artifact `dist/decode.js` is an obfuscator.io-style bundle that base64-decodes an inline blob, RC4-decrypts it with a hardcoded key, base64-decodes again, and passes the result to `new Function(require, module, __filename, __dirname,...)` — a decode-and-eval RCE primitive shipped alongside the main dropper. Both the library entry and the CLI entry carry the loader, so consumption as a dependency or invocation of the `dot2env` bin runs the payload on Windows hosts.
ENTRY
dist/cli.cjs (bin: ./dist/cli.cjs)
DESTINATION
- 2 exfil (custom-c2)
(values recorded in verified_iocs)
EXFIL
- System Information Collection in dist/cli.cjs: "process.platform"
OBFUSCATION
- Obfuscation: augmented proxied array function replacements in dist/decode.js
- Base64 Encoded Payload in dist/decode.js: "'GyfDqlLDsk5dVGzDpMOIw60bQwfCoMOWFAkFw7TDi8OiZBHCo8OPwpLDsm/Ch8Kyw6fCkcK4SGfDo1x..."
- Obfuscation (osm-deobfuscator): unknown in dist/decode.js
- Strings Extracted from Deobfuscated Code in dist/decode.js
- Obfuscation patterns: charCodeChain in dist/cli.cjs
- Obfuscation patterns: charCodeChain in dist/index.cjs
- recovered 2 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Reconstructed Obfuscated Domain in dist/cli.cjs: "powershell.exe"
- Dynamic Code Execution in dist/cli.cjs: "exec(n)"
- Shell Command Execution in dist/cli.cjs: "require("child_process")"
- Silent Process Execution in dist/cli.cjs: "stdio:"ignore""
- Very New NPM Publisher Account
PAYLOAD FILES
dist/cli.cjs (+ dist/index.cjs)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | dotenv-native | all (affected) | — |
Aliases
Browse GCVE Records
3,112 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.