CYBERSECURITYTRACKER
TRACKING7,578 stories in this site build1,625 vulnerability news stories in this site build
Vulnerabilities

envparse2

Review this malicious package's identity, affected versions, and published evidence.

Fixed response action, not model-generated: Remove the listed versions, and rotate any secrets the package could reach.

MAL-2026-16394

envparse2 in npm. Metadata and links only; package code and payload are never mirrored.

Loading the full malicious-package record.

Glossary