MAL-2026-14476

    Dashboard / Malicious Package / MAL-2026-14476

    MAL-2026-14476

    Published: 25 Aug 2026Last Modified: 25 Aug 2026

    Summary: Malicious code in ecobee2 (npm)

    Details: Source: amazon-inspector (42ebdeda4d4d0b3db14833d23a2d75a55e7e3f6af902f0ba6f545a970c0f09ba) package.json declares scripts.postinstall = 'node beacon.js', which runs automatically on npm install. beacon.js performs an HTTP GET to http://169.58.96.170:9001/cb with the installer's os.hostname() and the package name in the query string, disclosing host identity to a hardcoded bare-IP endpoint over cleartext HTTP at install time. The package README is a placeholder and no legitimate purpose is documented for this network activity.

    Affected packages

    Package

    Name: ecobee2

    Purl: pkg:npm/ecobee2

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.2