Malicious Package Affecting env-loader-cli package, versions [0,]


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-ENVLOADERCLI-16873942
  • published24 May 2026
  • disclosed23 May 2026
  • creditUnknown

Introduced: 23 May 2026

Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the env-loader-cli package.

Overview

env-loader-cli is a malicious package. This package contains malicious code, and its content was removed from the official package manager. The package was linked to a supply chain attack and contained code designed to steal developer secrets, crypto wallets, SSH keys, and cloud credentials across npm, PyPI, and Crates.io. While this package may be attempting to impersonate a valid organization or tool, there is no connection between that organization and this package's authorship.

References

CVSS Base Scores

version 4.0
version 3.1