MAL-2026-14475
Malicious code in ecobee-home (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (9a02620d2c1be5db8251957a24b2dacf01b146b1ee009169a9d828cb1f2a7425) The package's declared postinstall script runs beacon.js, which issues an HTTP GET to a hardcoded bare-IP endpoint (http://169.58.96.170:9001/cb) carrying the installer's hostname and the package name as query parameters. This fires automatically on npm install with no user opt-in. Reaching out to a bare-IP over plain HTTP with the installer's hostname on install is host-identifier reconnaissance/exfiltration to an attacker-controlled endpoint; the placeholder README and lookalike package name are consistent with a dependency-confusion / recon beacon rather than legitimate telemetry.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for ecobee-home (npm). Pin to a known-safe version or switch to an alternative.