Summary
Togoder Security scanned the npm package dotenv@18.0.5 on Oct 4, 2026. An AI review of 2 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Process spawning and shell command execution
NPS-2313E0456C33
The bundled 'dotenv run' CLI utility spawns child processes via child_process. On Windows, it falls back to spawning cmd.exe with a constructed command string using windowsVerbatimArguments. This is legitimate functionality for a CLI runner but represents a process-execution surface.
Environment variable harvesting
NPS-01F0A865FBAD
The code reads, parses, and injects environment variables from .env files into process.env. This is the documented behavior of the dotenv package but does touch environment variables broadly.
Credentials file access potential via user-specified paths
NPS-6E546CEDFD94
The CLI supports -f/--file options that accept arbitrary paths to read .env-style files. If invoked with hostile arguments this could be used to read arbitrary files that parse as dotenv format, but this is intended, user-controlled CLI behavior.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs | medium | This is the legitimate dotenv package with its 'dotenv run' CLI; no malicious exfiltration, backdoors, or obfuscated payloads were found, though it does spawn child processes and manipulate environment variables as intended functionality. |
| dist/config.cjs | safe | No malicious patterns detected |
Affected version ranges
None of the 2 scanned versions of dotenv are flagged high or critical. The latest scanned version, 18.0.5, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 18.0.5 | Needs review | 1 | 18.0.5 | |
| 17.2.3 | No issues | 1 | 17.2.3 | |
| 16.4.5 โ 16.6.1 | Not scanned | 3 | >=16.4.5 <=16.6.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of dotenv
Frequently asked questions
Is dotenv safe to use?
No confirmed malware was found in dotenv@18.0.5, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.
Does dotenv contain malware?
No malware was identified in dotenv@18.0.5 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was dotenv checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan dotenv together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in dotenv@18.0.5, cost nothing.