Togoder security

npm package security report

dotenv npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 18.0.5 Files reviewed 2 Size 10.7 KB Scanned

Summary

Togoder Security scanned the npm package dotenv@18.0.5 on Oct 4, 2026. An AI review of 2 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
3
low

Findings 3

low

Process spawning and shell command execution

NPS-2313E0456C33

The bundled 'dotenv run' CLI utility spawns child processes via child_process. On Windows, it falls back to spawning cmd.exe with a constructed command string using windowsVerbatimArguments. This is legitimate functionality for a CLI runner but represents a process-execution surface.

dist/index.cjs
low

Environment variable harvesting

NPS-01F0A865FBAD

The code reads, parses, and injects environment variables from .env files into process.env. This is the documented behavior of the dotenv package but does touch environment variables broadly.

dist/index.cjs
low

Credentials file access potential via user-specified paths

NPS-6E546CEDFD94

The CLI supports -f/--file options that accept arbitrary paths to read .env-style files. If invoked with hostile arguments this could be used to read arbitrary files that parse as dotenv format, but this is intended, user-controlled CLI behavior.

dist/index.cjs

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.cjs medium This is the legitimate dotenv package with its 'dotenv run' CLI; no malicious exfiltration, backdoors, or obfuscated payloads were found, though it does spawn child processes and manipulate environment variables as intended functionality.
dist/config.cjs safe No malicious patterns detected

Affected version ranges

None of the 2 scanned versions of dotenv are flagged high or critical. The latest scanned version, 18.0.5, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

16.4.518.0.5
VersionsVerdictCountRangeTop findings
18.0.5 Needs review 1 18.0.5
17.2.3 No issues 1 17.2.3
16.4.5 โ€“ 16.6.1 Not scanned 3 >=16.4.5 <=16.6.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of dotenv

VersionVerdictFilesScanned
18.0.5 Needs review 2 Oct 4, 2026
17.2.3 No issues 4 May 15, 2026

Frequently asked questions

Is dotenv safe to use?

No confirmed malware was found in dotenv@18.0.5, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.

Does dotenv contain malware?

No malware was identified in dotenv@18.0.5 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was dotenv checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan dotenv together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in dotenv@18.0.5, cost nothing.

Related security reports