MAL-2026-12141

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/beaver-ui-actions-button/MAL-2026-12141.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12141
Published
2026-08-05T08:54:01Z
Modified
2026-08-05T10:05:48.793036726Z
Summary
Malicious code in beaver-ui-actions-button (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1daeb30fbebca53883598794ed1662b3d15aca34b78d29257a477431a47201fd)

The package is published as a React components library but ships no React code. On library load, index.js auto-requires setup.js, which constructs obfuscated hostnames via runtime string-concatenation — five Cloudflare Workers mirrors (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with tin/tina/ldr/win subdomains of dl.well1.site as DNS fallbacks — and per-OS asset paths (/pkg/package, /pkg/package-arm64, /pkg/loadermac, /pkg/package.exe). lib/telemetry.js downloads the platform-specific binary, base64-decodes it, writes it to /var/tmp (or %TEMP% on Windows), applies mode 0755 via fs["chmod"+"Sync"], and executes it via require("child"+"process"). Sensitive APIs (child_process, chmodSync, platform, hostname, userInfo, arch) and every destination hostname are assembled at runtime from split string fragments to evade static analysis. setup.js additionally computes a sha256 fingerprint over os.hostname, os.userInfo().username, process.cwd(), process.version, and process.pid, and transmits it as installId to the same Cloudflare Workers / dl.well1.site endpoints. Destinations are not publisher infrastructure, are not version-pinned, and are not hash- or signature-verified; the fetched binaries are attacker-controlled and their content can change at any time.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "1daeb30fbebca53883598794ed1662b3d15aca34b78d29257a477431a47201fd",
            "modified_time": "2026-08-05T08:54:41Z",
            "id": "IN-MAL-2026-014467",
            "source": "amazon-inspector",
            "versions": [
                "5.4.7"
            ],
            "import_time": "2026-08-05T09:28:15.151869537Z"
        },
        {
            "sha256": "49748e442fa2052bf76f02ac4f362263dc350453c12822362b862d14269c875a",
            "modified_time": "2026-08-05T08:54:33Z",
            "import_time": "2026-08-05T09:28:14.939331014Z",
            "source": "amazon-inspector",
            "versions": [
                "5.4.8"
            ],
            "id": "IN-MAL-2026-014466"
        },
        {
            "import_time": "2026-08-05T09:28:14.464109767Z",
            "modified_time": "2026-08-05T08:54:01Z",
            "sha256": "88dc42cd4609b671c89441f7b8bc4f3e668a5b8dc43205fc468558b16057a8f3",
            "source": "amazon-inspector",
            "versions": [
                "12.3.9"
            ],
            "id": "IN-MAL-2026-014462"
        },
        {
            "import_time": "2026-08-05T09:28:15.23868182Z",
            "modified_time": "2026-08-05T08:54:51Z",
            "sha256": "c957f1b4e54333f515fa8ec1ba039d8ec44e42c43706adfe4577f0487f502c53",
            "source": "amazon-inspector",
            "versions": [
                "5.4.6"
            ],
            "id": "IN-MAL-2026-014468"
        },
        {
            "sha256": "f3cf861d67828519656b35fa43d2d7a3c7a13de5c1b35c149a716eaad048f866",
            "modified_time": "2026-08-05T08:54:26Z",
            "import_time": "2026-08-05T09:28:14.839633554Z",
            "source": "amazon-inspector",
            "versions": [
                "5.4.9"
            ],
            "id": "IN-MAL-2026-014465"
        }
    ]
}
References
Credits

Affected packages

npm / beaver-ui-actions-button

Package

Name
beaver-ui-actions-button
View open source insights on deps.dev
Purl
pkg:npm/beaver-ui-actions-button

Affected ranges

Affected versions

5.*
5.4.6
5.4.7
5.4.8
5.4.9
12.*
12.3.9

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/beaver-ui-actions-button/MAL-2026-12141.json"
indicators
{
    "evidence_files": [
        {
            "sha256": "96a0461092fc35fb20c083084df74b942199d022adfa9b7af7a2d0f87f417612",
            "tlsh": "6a9162080ed579360284e3e96a2a4447e89604433ac8f6487a4ff35c4f98139877ffaf",
            "path": "setup.js"
        },
        {
            "sha256": "9d47715b5018d122cfe498587342ccd84ae4ea142d15c78dc4681b0a6efd4460",
            "tlsh": "09733f4966fb1021826370685fbb40437635c4072a4aed5dba9c43ec9f8db3896f1fb9",
            "path": "lib/telemetry.js"
        }
    ],
    "package_integrity": [
        {
            "filename": "beaver-ui-actions-button-5.4.7.tgz",
            "hashes": {
                "sha1": "dcbff6fc230ff8fd7b4961825a8153de66691b82",
                "sha512_sri": "sha512-p+mxmG7ZGgJD/Q5V2+lFtXvIcYrW60GIN2+vAOkY7ucTTr4t78HsL0LLCnxYCNPFQusDxD1XxyjvUxT/ZIqdbQ=="
            }
        }
    ]
}