dotenv-extend

MAL-2025-192743

npmmalware12/23/2025
Description

Malicious code in dotenv-extend (npm)

Indicators of Compromise
SHA256 Hashes (3)
7ef0bc2453e5610efd0011a08cecb1021a4d5a38aee276a269ad3185bb40925a
b36b33fa03b9dafefe167d7891f649dc39ac77a18a67a25c44d0d647dd3518e9
45b0680450bdae4a5bf617ea9db459f5b4cf953f709747eec6ee7d06883bdfc2
Details
Ecosystemnpm
Attack Typemalware
Published12/23/2025
Affected Versions
0
Aliases
GHSA-jr68-9xqf-rp8q
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001