MAL-2026-16074
Malicious code in easypanel-deploy (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (0ac486399ab6c99cf83bfcf80e487c414fd29430e27f0d929ff7034ed333c7e8) The package's preinstall lifecycle script runs automatically on `npm install` and collects installer-side identifiers — `os.hostname()`, `os.userInfo().username`, the current working directory, and CI-related environment variable names — base64url-encodes them, and sends them to a hardcoded third-party out-of-band collector under `oob.lyomeri.com` via both a DNS lookup (`easypanel-deploy.<chunk>daco3v4q6f49egu1ds1gwjnsjb88s5kcp.oob.lyomeri.com`) and an HTTP GET request to the same host. The behavior fires without user consent on install, exfiltrates host reconnaissance data to an attacker-controlled endpoint, and is consistent with a dependency-confusion / beacon package. An in-source comment labeling this as a 'benign canary' does not change the observable behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for easypanel-deploy (npm). Pin to a known-safe version or switch to an alternative.