-= Per source details. Do not edit below this line.=-
The package is published as a React components library but ships no React code. On library load, index.js auto-requires setup.js, which constructs obfuscated hostnames via runtime string-concatenation — five Cloudflare Workers mirrors (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with tin/tina/ldr/win subdomains of dl.well1.site as DNS fallbacks — and per-OS asset paths (/pkg/package, /pkg/package-arm64, /pkg/loadermac, /pkg/package.exe). lib/telemetry.js downloads the platform-specific binary, base64-decodes it, writes it to /var/tmp (or %TEMP% on Windows), applies mode 0755 via fs["chmod"+"Sync"], and executes it via require("child"+"process"). Sensitive APIs (child_process, chmodSync, platform, hostname, userInfo, arch) and every destination hostname are assembled at runtime from split string fragments to evade static analysis. setup.js additionally computes a sha256 fingerprint over os.hostname, os.userInfo().username, process.cwd(), process.version, and process.pid, and transmits it as installId to the same Cloudflare Workers / dl.well1.site endpoints. Destinations are not publisher infrastructure, are not version-pinned, and are not hash- or signature-verified; the fetched binaries are attacker-controlled and their content can change at any time.
{
"malicious-packages-origins": [
{
"sha256": "1daeb30fbebca53883598794ed1662b3d15aca34b78d29257a477431a47201fd",
"modified_time": "2026-08-05T08:54:41Z",
"id": "IN-MAL-2026-014467",
"source": "amazon-inspector",
"versions": [
"5.4.7"
],
"import_time": "2026-08-05T09:28:15.151869537Z"
},
{
"sha256": "49748e442fa2052bf76f02ac4f362263dc350453c12822362b862d14269c875a",
"modified_time": "2026-08-05T08:54:33Z",
"import_time": "2026-08-05T09:28:14.939331014Z",
"source": "amazon-inspector",
"versions": [
"5.4.8"
],
"id": "IN-MAL-2026-014466"
},
{
"import_time": "2026-08-05T09:28:14.464109767Z",
"modified_time": "2026-08-05T08:54:01Z",
"sha256": "88dc42cd4609b671c89441f7b8bc4f3e668a5b8dc43205fc468558b16057a8f3",
"source": "amazon-inspector",
"versions": [
"12.3.9"
],
"id": "IN-MAL-2026-014462"
},
{
"import_time": "2026-08-05T09:28:15.23868182Z",
"modified_time": "2026-08-05T08:54:51Z",
"sha256": "c957f1b4e54333f515fa8ec1ba039d8ec44e42c43706adfe4577f0487f502c53",
"source": "amazon-inspector",
"versions": [
"5.4.6"
],
"id": "IN-MAL-2026-014468"
},
{
"sha256": "f3cf861d67828519656b35fa43d2d7a3c7a13de5c1b35c149a716eaad048f866",
"modified_time": "2026-08-05T08:54:26Z",
"import_time": "2026-08-05T09:28:14.839633554Z",
"source": "amazon-inspector",
"versions": [
"5.4.9"
],
"id": "IN-MAL-2026-014465"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/beaver-ui-actions-button/MAL-2026-12141.json"
{
"evidence_files": [
{
"sha256": "96a0461092fc35fb20c083084df74b942199d022adfa9b7af7a2d0f87f417612",
"tlsh": "6a9162080ed579360284e3e96a2a4447e89604433ac8f6487a4ff35c4f98139877ffaf",
"path": "setup.js"
},
{
"sha256": "9d47715b5018d122cfe498587342ccd84ae4ea142d15c78dc4681b0a6efd4460",
"tlsh": "09733f4966fb1021826370685fbb40437635c4072a4aed5dba9c43ec9f8db3896f1fb9",
"path": "lib/telemetry.js"
}
],
"package_integrity": [
{
"filename": "beaver-ui-actions-button-5.4.7.tgz",
"hashes": {
"sha1": "dcbff6fc230ff8fd7b4961825a8153de66691b82",
"sha512_sri": "sha512-p+mxmG7ZGgJD/Q5V2+lFtXvIcYrW60GIN2+vAOkY7ucTTr4t78HsL0LLCnxYCNPFQusDxD1XxyjvUxT/ZIqdbQ=="
}
}
]
}