LWA-2026-11866 MAL-2026-16074 ↗ confirmed malware

easypanel-deploy@1.0.0

Malicious code in easypanel-deploy (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package's preinstall hook (preinstall.js) runs on install and collects host fingerprint data — hostname, username, current working directory, and the names of CI-related environment variables present (GITHUB_, GITLAB_, BUILD_, JENKINS, CIRCLE, TF_BUILD, BITBUCKET, DRONE, AWS_CODEBUILD). It base64url-encodes this and exfiltrates it to the attacker-controlled host easypanel-deploy[.]daco3v4q6f49egu1ds1gwjnsjb88s5kcp[.]oob[.]lyomeri[.]com via both a DNS lookup and an HTTP GET to /npm/<encoded-data>. The exfiltration is wrapped in try/catch and always exits 0 so the install appears to succeed.

analyzed by
Leitwacht
first seen
Sep 3, 2026, 06:02 PM
analyzed
Sep 3, 2026, 06:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.