[email protected]: reverse engineering an npm supply chain dropper
[email protected] is a malicious npm package masquerading as a dotenv variant. Full walkthrough of the obfuscated dropper, the encoded PowerShell it builds, and the DonutLoader plus Epsilon Stealer payload it pulls from a Cloudflare Tunnel.