LWA-2026-11869 MAL-2026-16072 ↗ confirmed malware

easypanel-agent@1.0.0

Malicious code in easypanel-agent (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

The preinstall hook (preinstall.js) runs on install and collects the host's hostname, username, current working directory, and the names of CI-related environment variables, then exfiltrates this data to the remote host easypanel-agent[.]daco3v4q6f49egu1ds1gwjnsjb88s5kcp[.]oob[.]lyomeri[.]com via both a DNS lookup (data chunked into the subdomain) and an HTTP request to /npm/<payload>. The package is a client library with no repository and no declared purpose for this network activity.

analyzed by
Leitwacht
first seen
Sep 3, 2026, 06:02 PM
analyzed
Sep 3, 2026, 06:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.