{"id":"MAL-2026-16074","summary":"Malicious code in easypanel-deploy (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0ac486399ab6c99cf83bfcf80e487c414fd29430e27f0d929ff7034ed333c7e8)\nThe package's preinstall lifecycle script runs automatically on `npm install` and collects installer-side identifiers — `os.hostname()`, `os.userInfo().username`, the current working directory, and CI-related environment variable names — base64url-encodes them, and sends them to a hardcoded third-party out-of-band collector under `oob.lyomeri.com` via both a DNS lookup (`easypanel-deploy.\u003cchunk\u003edaco3v4q6f49egu1ds1gwjnsjb88s5kcp.oob.lyomeri.com`) and an HTTP GET request to the same host. The behavior fires without user consent on install, exfiltrates host reconnaissance data to an attacker-controlled endpoint, and is consistent with a dependency-confusion / beacon package. An in-source comment labeling this as a 'benign canary' does not change the observable behavior.\n","modified":"2026-09-09T05:45:04.565977654Z","published":"2026-09-09T05:33:34Z","database_specific":{"malicious-packages-origins":[{"sha256":"0ac486399ab6c99cf83bfcf80e487c414fd29430e27f0d929ff7034ed333c7e8","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019842","import_time":"2026-09-09T05:40:09.171798936Z","modified_time":"2026-09-09T05:33:34Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/easypanel-deploy/v/1.0.0"}],"affected":[{"package":{"name":"easypanel-deploy","ecosystem":"npm","purl":"pkg:npm/easypanel-deploy"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/easypanel-deploy/MAL-2026-16074.json","indicators":{"evidence_files":[{"path":"preinstall.js","sha256":"7ca4e5e1b3ab8567dbd83857dc9a3d8815c456cb53e20091fff6e048a49c94ae","tlsh":"e31123b0d16052bd056162c0a86b46a292b7efd130e2cdc0783e66416fd26d20bf38fe"}],"package_integrity":[{"filename":"easypanel-deploy-1.0.0.tgz","hashes":{"sha1":"3ec945133362b05e94d04a38de759850af3dd155","sha512_sri":"sha512-PmOLDtx8TosAagtcHysPjkrFTHdXzV5gsYAkwuSWU/8zkJ+zFrjVlFOOKWgJCI1PYNiL/H1PDrmr6Oawun+i9g=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}