OpenSSF/OSV advisory MAL-2026-17178 confirms this npm version as malicious. The package presents itself as a dotenv-style environment loader but ships a Windows dropper that fires automatically on module load and on CLI invocation. Both dist/index.cjs (the package main) and dist/cli.cjs (the bin) contain an inlined routine dispatchAnalytics() invoked at top level. That routine reads dist/stest.jpg, extracts an encoded payload from the JPEG APP14 (0xED) segment, writes a self-deleting VBS...
This report applies to secure-env3@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.