VDB
KO

MAL-2026-14475

Malicious code in ecobee-home (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9a02620d2c1be5db8251957a24b2dacf01b146b1ee009169a9d828cb1f2a7425) The package's declared postinstall script runs beacon.js, which issues an HTTP GET to a hardcoded bare-IP endpoint (http://169.58.96.170:9001/cb) carrying the installer's hostname and the package name as query parameters. This fires automatically on npm install with no user opt-in. Reaching out to a bare-IP over plain HTTP with the installer's hostname on install is host-identifier reconnaissance/exfiltration to an attacker-controlled endpoint; the placeholder README and lookalike package name are consistent with a dependency-confusion / recon beacon rather than legitimate telemetry.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / ecobee-home

No fixed version published yet for ecobee-home (npm). Pin to a known-safe version or switch to an alternative.

References