MAL-2026-15897
Dashboard / Malicious Package / MAL-2026-15897
MAL-2026-15897
Summary: Malicious code in easypanel-core (npm)
Details: Source: amazon-inspector (4cb013a465c19126feba2006a81f33d65cc64b269e3da8ffe4e8284c7defa3cc) easypanel-core ships an inert `module.exports = {}` main and places all functionality in a preinstall lifecycle script. On `npm install`, preinstall.js collects os.hostname(), os.userInfo().username, process.cwd(), and the names of CI-related environment variables, base64url-encodes them, and transmits the data to `*.daco3v4q6f49egu1ds1gwjnsjb88s5kcp.oob.lyomeri.com` via both a DNS subdomain lookup and an HTTP GET to `/npm/<encoded>`. The package name mimics the easypanel project and the description advertises a 'client library', while the shipped library exports nothing and provides no functionality — the install-time beacon is the sole behavior.
Affected packages
Package
Name: easypanel-core
Purl: pkg:npm/easypanel-core
Affected ranges
Type: N/A
Events:
