MAL-2026-15895
Dashboard / Malicious Package / MAL-2026-15895
MAL-2026-15895
Summary: Malicious code in easypanel-app (npm)
Details: Source: amazon-inspector (2744a6f0dfde1930ab560731e54cb8a1e1c8dc61a2072705498ddcaa6dd1a592) The package's preinstall lifecycle script runs automatically on npm install and collects installer identity (os.hostname(), os.userInfo().username, process.cwd()) along with the names of CI-related environment variables. The collected data is JSON-serialized, base64url-encoded, chunked into DNS label form, and exfiltrated to a hardcoded third-party out-of-band collector at *.oob.lyomeri.com via both a dns.lookup() call and an HTTP GET to easypanel-app.daco3v4q6f49egu1ds1gwjnsjb88s5kcp.oob.lyomeri.com. The name mimics the legitimate Easypanel project and the shape (preinstall + host/username/cwd + OOB DNS+HTTP beacon to a per-package subdomain) is a dependency-confusion reconnaissance beacon, disclosing installer identity and internal-package-name existence to a third party regardless of any 'benign canary' self-label.
Affected packages
Package
Name: easypanel-app
Purl: pkg:npm/easypanel-app
Affected ranges
Type: N/A
Events:
