VDB
Sign up

MAL-2026-16073

Malicious code in easypanel-api-client (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (cef6da51fcc215c514680417cfd3bacb5725b91a5b4a058fd6d2b161106209b0) The package ships an empty library body (index.js exports {}) and a preinstall lifecycle script that runs automatically on npm install. The preinstall script collects installer-side identifiers — hostname, username, current working directory, and the names of CI-related environment variables — base64url-encodes them, and transmits them via both a DNS lookup and an HTTP request to a subdomain of oob.lyomeri.com (e.g. easypanel-api-client.<encoded-chunk>.oob.lyomeri.com, with the HTTP variant POSTing to /npm/<encoded>). The package has no functional code beyond this beacon, matching the dependency-confusion / namespace-squat research-beacon shape targeting internal package names.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/easypanel-api-client

No fixed version published yet for easypanel-api-client (npm). Pin to a known-safe version or switch to an alternative.

References