easypanel-deploy@1.0.0
Vulnerability report · Last retrieved from osv.dev September 9, 2026 at 6:10 AM UTC
OSV ID
MAL-2026-16074
Ecosystem
npm
Summary
The package's preinstall lifecycle script runs automatically on npm install and collects installer-side identifiers — os.hostname(), os.userInfo().username, the current working directory, and CI-related environment variable names — base64url-encodes them, and sends them to a hardcoded third-party out-of-band collector under oob.lyomeri.com via both a DNS lookup (easypanel-deploy.<chunk>daco3v4q6f49egu1ds1gwjnsjb88s5kcp.oob.lyomeri.com) and an HTTP GET request to the same host. The behavior fires without user consent on install, exfiltrates host reconnaissance data to an attacker-controlled endpoint, and is consistent with a dependency-confusion / beacon package. An in-source comment labeling this as a 'benign canary' does not change the observable behavior.
Source: amazon-inspector (0ac486399ab6c99cf83bfcf80e487c414fd29430e27f0d929ff7034ed333c7e8)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.