VDB
EN

MAL-2026-14474

Malicious code in ecobee-api (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (bebaf39f3f17cfdfbddac8bb4f92aaa1fd600b7f0a69def35d879ebe5d90f14f) On `npm install`, ecobee-api runs `node beacon.js` via its postinstall lifecycle script. The beacon issues an HTTP GET to the hardcoded bare-IP endpoint http://169.58.96.170:9001/cb, passing the installer's hostname (os.hostname()) and the package name as query parameters. The package ships no functional library code — package.json declares an UNLICENSED 'Utility package' with a name resembling the Ecobee vendor, and the only substantive shipped file is the beacon. This is the shape of a dependency-confusion / typosquat recon beacon: it confirms install-time code execution on the victim host and identifies the host to the operator of 169.58.96.170 over plain HTTP.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / ecobee-api

No fixed version published yet for ecobee-api (npm). Pin to a known-safe version or switch to an alternative.

참고