MAL-2026-15896
Malicious code in easypanel-client (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (1675d70b09ce1f826b69fbfcee3cf56a81c49c37fa4fb4bdafd4f72b736880f8) The package's npm preinstall hook collects the installer's hostname, OS username, current working directory, and CI-related environment variable names, base64url-encodes them, and transmits them to the hardcoded out-of-band host easypanel-client.<subdomain>.oob.lyomeri.com via both a DNS lookup and an HTTP GET request. The shipped index.js is empty (module.exports = {}), so the only effect of installing this package is the install-time beacon. The package name and structure are consistent with a dependency-confusion probe targeting internal easypanel-* names.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for easypanel-client (npm). Pin to a known-safe version or switch to an alternative.