Malicious code in core-dotenv (npm)
The core-dotenv npm package version 1.4.1 contains malicious code that fetches and executes remote code at runtime. This behavior occurs when calling its config() or get() functions, which trigger an obfuscated HTTPS request to a remote server. The response is executed with full Node.js privileges, allowing arbitrary code execution on the host. This package should be considered fully compromised, and any system using it is at high risk.
AI Analysis
Technical Summary
core-dotenv version 1.4.1 masquerades as a dotenv/env-var wrapper but includes malicious functionality. When its config() or get() methods are called, it makes an obfuscated HTTPS request to realase-0626.vercel.app/api/v1. The response JSON's 'parser' field is executed in a Node.js VM context with access to the Function constructor and require, enabling remote code execution with full Node capabilities. This behavior is unrelated to legitimate dotenv functionality and is designed to evade static analysis. Systems with this package installed should be considered fully compromised.
Potential Impact
Systems running core-dotenv 1.4.1 are at risk of full compromise due to remote code execution capabilities granted by the malicious package. Attackers can execute arbitrary code with Node.js privileges, potentially accessing secrets, keys, and other sensitive data. The compromise is severe enough that all secrets and keys on affected systems should be rotated from a clean environment. Simply removing the package may not remove all malicious artifacts or backdoors.
Mitigation Recommendations
Remove the core-dotenv package version 1.4.1 immediately. Rotate all secrets and keys stored on affected systems from a different, uncompromised computer. Because the package grants full control to an attacker, assume the system is fully compromised and perform a thorough incident response. There is no official patch or fix available; remediation involves removal and secret rotation.
Malicious code in core-dotenv (npm)
Description
The core-dotenv npm package version 1.4.1 contains malicious code that fetches and executes remote code at runtime. This behavior occurs when calling its config() or get() functions, which trigger an obfuscated HTTPS request to a remote server. The response is executed with full Node.js privileges, allowing arbitrary code execution on the host. This package should be considered fully compromised, and any system using it is at high risk.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
core-dotenv version 1.4.1 masquerades as a dotenv/env-var wrapper but includes malicious functionality. When its config() or get() methods are called, it makes an obfuscated HTTPS request to realase-0626.vercel.app/api/v1. The response JSON's 'parser' field is executed in a Node.js VM context with access to the Function constructor and require, enabling remote code execution with full Node capabilities. This behavior is unrelated to legitimate dotenv functionality and is designed to evade static analysis. Systems with this package installed should be considered fully compromised.
Potential Impact
Systems running core-dotenv 1.4.1 are at risk of full compromise due to remote code execution capabilities granted by the malicious package. Attackers can execute arbitrary code with Node.js privileges, potentially accessing secrets, keys, and other sensitive data. The compromise is severe enough that all secrets and keys on affected systems should be rotated from a clean environment. Simply removing the package may not remove all malicious artifacts or backdoors.
Mitigation Recommendations
Remove the core-dotenv package version 1.4.1 immediately. Rotate all secrets and keys stored on affected systems from a different, uncompromised computer. Because the package grants full control to an attacker, assume the system is fully compromised and perform a thorough incident response. There is no official patch or fix available; remediation involves removal and secret rotation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10631
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a577efb68715ace43b41e2f
Added to database: 07/15/2026, 12:37:15 UTC
Last enriched: 08/20/2026, 16:59:25 UTC
Last updated: 09/13/2026, 13:41:16 UTC
Views: 117
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.