LWA-2026-11868 MAL-2026-15899 ↗ confirmed malware

easypanel-docker@1.0.0

Malicious code in easypanel-docker (npm)

T1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The preinstall hook (preinstall.js) runs on install and silently collects the host's hostname, OS username, current working directory, and the names of CI/build environment variables, then base64url-encodes this metadata and exfiltrates it to the domain oob[.]lyomeri[.]com via two channels: a DNS lookup to easypanel-docker.<data>.daco3v4q6f49egu1ds1gwjnsjb88s5kcp[.]oob[.]lyomeri[.]com and an HTTP POST to easypanel-docker[.]daco3v4q6f49egu1ds1gwjnsjb88s5kcp[.]oob[.]lyomeri[.]com/npm/<data>. The package is named easypanel-docker and describes itself only as a "client library".

analyzed by
Leitwacht
first seen
Sep 3, 2026, 06:02 PM
analyzed
Sep 3, 2026, 06:04 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.