Runs dotenv preflight checks at install time
An automatic install hook launches obfuscated code that searches user directories for environment files and secret-like material. The code submits collected data to an obscured remote endpoint.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs index.js automatically through a postinstall hook.
package.jsonView on unpkg · L5Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1The heavily obfuscated entrypoint imports filesystem and operating-system modules.
index.jsView on unpkg · L1The entrypoint recursively walks files and selects names beginning with .env.
index.jsView on unpkg · L1It defines patterns for seed phrases, private keys, tokens, passwords, and other secrets.
index.jsView on unpkg · L1This report applies to dotenv-precheck@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs index.js automatically through a postinstall hook.
package.jsonView on unpkg · L5Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1The heavily obfuscated entrypoint imports filesystem and operating-system modules.
index.jsView on unpkg · L1The entrypoint recursively walks files and selects names beginning with .env.
index.jsView on unpkg · L1It defines patterns for seed phrases, private keys, tokens, passwords, and other secrets.
index.jsView on unpkg · L1