MAL-2026-14476
Dashboard / Malicious Package / MAL-2026-14476
MAL-2026-14476
Published: 25 Aug 2026Last Modified: 25 Aug 2026
Summary: Malicious code in ecobee2 (npm)
Details: Source: amazon-inspector (42ebdeda4d4d0b3db14833d23a2d75a55e7e3f6af902f0ba6f545a970c0f09ba) package.json declares scripts.postinstall = 'node beacon.js', which runs automatically on npm install. beacon.js performs an HTTP GET to http://169.58.96.170:9001/cb with the installer's os.hostname() and the package name in the query string, disclosing host identity to a hardcoded bare-IP endpoint over cleartext HTTP at install time. The package README is a placeholder and no legitimate purpose is documented for this network activity.
References: https://www.npmjs.com/package/ecobee2/v/0.0.2
Affected packages
Package
Name: ecobee2
Purl: pkg:npm/ecobee2
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
0.0.2
