OpenSSF/OSV advisory MAL-2026-16394 confirms this npm version as malicious. On require() of the package's main entry and on invocation of the `dot2env` CLI, the module reads the bundled `dist/stest.jpg`, parses JPEG markers, and extracts a UTF-8 string from the APP13 (0xED) segment. The extracted string is passed as an argument to `powershell.exe -NoProfile -NonInteractive -EncodedCommand`, launched hidden on Windows via a VBS relay dropped to `%TMP%` and invoked through `wscript.exe`...
This report applies to envparse2@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.