Runs dotenv preflight checks at install time
Automatic installation triggers an obfuscated secret-harvesting program. The program scans files and exports collected environment and wallet-related data to an external service.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs index.js automatically through a postinstall hook.
package.jsonView on unpkg · L5Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1The obfuscated entrypoint creates collections for environment-file contents, secret variables, private keys, and seed phrases.
index.jsView on unpkg · L1It recursively reads files, preserves .env content, and applies secret-extraction routines.
index.jsView on unpkg · L1It sends collected data with fetch to an obfuscated external destination, including a chat identifier and multipart payload.
index.jsView on unpkg · L1This report applies to dotenv-precheck@1.1.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs index.js automatically through a postinstall hook.
package.jsonView on unpkg · L5Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1The obfuscated entrypoint creates collections for environment-file contents, secret variables, private keys, and seed phrases.
index.jsView on unpkg · L1It recursively reads files, preserves .env content, and applies secret-extraction routines.
index.jsView on unpkg · L1It sends collected data with fetch to an obfuscated external destination, including a chat identifier and multipart payload.
index.jsView on unpkg · L1