VDB
Sign up

MAL-2026-15896

Malicious code in easypanel-client (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1675d70b09ce1f826b69fbfcee3cf56a81c49c37fa4fb4bdafd4f72b736880f8) The package's npm preinstall hook collects the installer's hostname, OS username, current working directory, and CI-related environment variable names, base64url-encodes them, and transmits them to the hardcoded out-of-band host easypanel-client.<subdomain>.oob.lyomeri.com via both a DNS lookup and an HTTP GET request. The shipped index.js is empty (module.exports = {}), so the only effect of installing this package is the install-time beacon. The package name and structure are consistent with a dependency-confusion probe targeting internal easypanel-* names.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/easypanel-client

No fixed version published yet for easypanel-client (npm). Pin to a known-safe version or switch to an alternative.

References