{"id":"MAL-2026-16075","summary":"Malicious code in easypanel-hosting (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (db6a378b33bb2f33088ed90db4ac48e81368e30d5ef38578dca3b4345e9cb06b)\neasypanel-hosting@1.0.0 ships a stub index.js (`module.exports = {}`) and an npm preinstall lifecycle script that collects the installer's hostname, username, current working directory, and CI-related environment variable names, base64url-encodes them, and sends them off-host via a DNS lookup and an HTTP request to a hardcoded out-of-band subdomain under lyomeri.com (e.g. `easypanel-hosting.\u003ctoken\u003e.oob.lyomeri.com`, with the encoded payload placed in the DNS label and in the HTTP path `/npm/\u003cencoded\u003e`). The exfiltration fires automatically on `npm install` before any user code runs. The empty main module and package name resembling a hosting-adjacent product are consistent with a dependency-confusion or reconnaissance probe; regardless of framing, installer identity metadata leaves the machine unconditionally to an author-controlled OOB collector.\n","modified":"2026-09-09T05:45:04.740875476Z","published":"2026-09-09T05:33:15Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-019840","import_time":"2026-09-09T05:40:09.116346755Z","modified_time":"2026-09-09T05:33:15Z","sha256":"db6a378b33bb2f33088ed90db4ac48e81368e30d5ef38578dca3b4345e9cb06b","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/easypanel-hosting/v/1.0.0"}],"affected":[{"package":{"name":"easypanel-hosting","ecosystem":"npm","purl":"pkg:npm/easypanel-hosting"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"951127b0d160927d056161c0685f46969177dfd130e2cdc0683a66815fd26920bb3cfd","path":"preinstall.js","sha256":"49433cbd5249046960dd19024fa773b621c073ce33b5c7d244710c0f0f424b09"},{"path":"index.js","sha256":"8222b8169ee86f25cdccd84d340340060ae3f0cff55e2ea9d344d7c332733b71"}],"package_integrity":[{"filename":"easypanel-hosting-1.0.0.tgz","hashes":{"sha1":"6a3ea4bf3b8fabe813503031c0c5d85278cdb0b6","sha512_sri":"sha512-ZcIMJKNke5E7ZQR4JHkLFF+eiS0XFmSS6UN8/xITeJoyrbf30JCr1XV87eo+ie0YRAwZvIeZv0HgXOVQqrgk3Q=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/easypanel-hosting/MAL-2026-16075.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}