VDB
Sign up

MAL-2026-15895

Malicious code in easypanel-app (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2744a6f0dfde1930ab560731e54cb8a1e1c8dc61a2072705498ddcaa6dd1a592) The package's preinstall lifecycle script runs automatically on npm install and collects installer identity (os.hostname(), os.userInfo().username, process.cwd()) along with the names of CI-related environment variables. The collected data is JSON-serialized, base64url-encoded, chunked into DNS label form, and exfiltrated to a hardcoded third-party out-of-band collector at *.oob.lyomeri.com via both a dns.lookup() call and an HTTP GET to easypanel-app.daco3v4q6f49egu1ds1gwjnsjb88s5kcp.oob.lyomeri.com. The name mimics the legitimate Easypanel project and the shape (preinstall + host/username/cwd + OOB DNS+HTTP beacon to a per-package subdomain) is a dependency-confusion reconnaissance beacon, disclosing installer identity and internal-package-name existence to a third party regardless of any 'benign canary' self-label.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/easypanel-app

No fixed version published yet for easypanel-app (npm). Pin to a known-safe version or switch to an alternative.

References