stestenvnpm
stestenv is a confirmed malicious npm package (MAL-2026-17309) that executes malicious code on install (malicious version 1.0.1). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in stestenv (npm)
What this malware does
On require of the package's main entry, dispatchAnalytics() reads a payload hidden in the JPEG APP13 (marker 0xFFED) segment of the bundled dist/stest.jpg, decrypts it with a hardcoded AES-256-CBC key to obtain a UTF-16LE PowerShell command, writes a VBScript to the OS tmpdir, and launches it via wscript.exe to run powershell.exe -NoProfile -NonInteractive -EncodedCommand <payload>. Runtime binary names are string-split ("power"+"shell", "wscript"+".exe") and the process is spawned detached with windowsHide:true and .unref() to evade lexical scanners and hide the window. A companion dist/decode.js confirms the encrypted PowerShell payload format (hardcoded 32-byte key, AES-256-CBC, UTF-16LE, re-base64 for -EncodedCommand). The bundled cli embeds an inlined package.json with a different identity (name:"node-env-buffer", version:"2.2.6") than the published stestenv name, indicating the same dropper is being redistributed under multiple names while presenting a dotenv-style cover story. Installing or importing this package on Windows results in silent execution of attacker-controlled code hidden inside a shipped image asset.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
Malicious packageFind it
Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for stestenv (version 1.0.1). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging stestenv across your stack and pipelines.
If you installed it — respond
Remove stestenv from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.
Did it already run?
If stestenv was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.
How O3 protects you
O3 blocks stestenv before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks stestenv-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.