easypanel-cli@1.0.0
Malicious code in easypanel-cli (npm)
Analysis
The preinstall hook (preinstall.js) runs on install and silently collects the host's hostname, username, current working directory, and the names of CI environment variables (GITHUB_, GITLAB_, BUILD_, JENKINS, CIRCLE, TF_BUILD, BITBUCKET, DRONE, AWS_CODEBUILD). This data is base64url-encoded and exfiltrated to the attacker-controlled domain oob[.]lyomeri[.]com via both a DNS lookup (easypanel-cli.<data>daco3v4q6f49egu1ds1gwjnsjb88s5kcp[.]oob[.]lyomeri[.]com) and an HTTP POST to /npm/<payload> on the same host. The hook always exits 0 so the install appears to succeed.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 06:00 PM
- analyzed
- Sep 3, 2026, 06:01 PM
Related advisories
- fieldbase-webapplication-buildtools@99.99.99
- @quantixfinance/database@1.0.1
- @quantixfinance/token@1.0.1
- @quantixfinance/contracts@1.0.0
- @quantixfinance/wallet@1.0.0
- @quantixfinance/common@1.0.0
- @quantixfinance/sdk@1.0.0
- @quantixfinance/api@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.