OpenSSF/OSV advisory MAL-2026-16072 confirms this npm version as malicious. The package's preinstall lifecycle script (preinstall.js) executes automatically on `npm install` and collects the installer's hostname, OS username, current working directory, and CI-related environment variable names. The collected data is base64-encoded and transmitted to a hardcoded out-of-band collector under lyomeri.com via both a DNS lookup (encoding data into a subdomain label under...
This report applies to easypanel-agent@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.