MAL-2026-16073
Malicious code in easypanel-api-client (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (cef6da51fcc215c514680417cfd3bacb5725b91a5b4a058fd6d2b161106209b0) The package ships an empty library body (index.js exports {}) and a preinstall lifecycle script that runs automatically on npm install. The preinstall script collects installer-side identifiers — hostname, username, current working directory, and the names of CI-related environment variables — base64url-encodes them, and transmits them via both a DNS lookup and an HTTP request to a subdomain of oob.lyomeri.com (e.g. easypanel-api-client.<encoded-chunk>.oob.lyomeri.com, with the HTTP variant POSTing to /npm/<encoded>). The package has no functional code beyond this beacon, matching the dependency-confusion / namespace-squat research-beacon shape targeting internal package names.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for easypanel-api-client (npm). Pin to a known-safe version or switch to an alternative.