easypanel-docker@1.0.0
Malicious code in easypanel-docker (npm)
Analysis
The preinstall hook (preinstall.js) runs on install and silently collects the host's hostname, OS username, current working directory, and the names of CI/build environment variables, then base64url-encodes this metadata and exfiltrates it to the domain oob[.]lyomeri[.]com via two channels: a DNS lookup to easypanel-docker.<data>.daco3v4q6f49egu1ds1gwjnsjb88s5kcp[.]oob[.]lyomeri[.]com and an HTTP POST to easypanel-docker[.]daco3v4q6f49egu1ds1gwjnsjb88s5kcp[.]oob[.]lyomeri[.]com/npm/<data>. The package is named easypanel-docker and describes itself only as a "client library".
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 06:02 PM
- analyzed
- Sep 3, 2026, 06:04 PM
Related advisories
- easypanel-hosting@1.0.0
- easypanel-deploy@1.0.0
- easypanel-cli@1.0.0
- fieldbase-webapplication-buildtools@99.99.99
- @quantixfinance/database@1.0.1
- @quantixfinance/token@1.0.1
- @quantixfinance/contracts@1.0.0
- @quantixfinance/wallet@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.