MAL-2026-12144

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/beaver-ui-drawer/MAL-2026-12144.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12144
Published
2026-08-05T08:51:04Z
Modified
2026-08-05T10:05:50.161415967Z
Summary
Malicious code in beaver-ui-drawer (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e7ff4f4ef11d2ff4bbba6d98547a1f6c1e5834739b4943f581e057abb9e313ce)

beaver-ui-drawer@9.4.10 ships a postinstall script (setup.js) that assembles network destinations at runtime by joining split string fragments to hide them from static inspection, resolving to a rotating set of Cloudflare Workers subdomains (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with a DNS TXT fallback under *.dl.well1.site (e.g. tin.dl.well1.site). The script downloads a platform-specific binary, writes it to /var/tmp/.cache<rand> on Unix or %TEMP%\dotnetdiag<rand>.exe on Windows, chmods 0755, launches it detached with stdio redirected to /dev/null, and unlinks the file. index.js contains a top-level try { require('./setup'); } catch(_) {} that re-invokes the same drop-and-execute path on require(), providing a second execution path when npm install --ignore-scripts is used; a mtime marker at /tmp/.analyticsstate with a 6-hour TTL suppresses repeated downloads. The package is advertised only as a UI drawer component; there is no legitimate reason for a UI library to fetch and execute unsigned binaries from anonymous Cloudflare Workers hosts. The payload is unversioned, unhashed, delivered from infrastructure unrelated to the stated package purpose, staged to hidden filenames mimicking system tooling (dotnetdiag,.cache_,.analytics_state), and self-deletes after launch.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-014446",
            "import_time": "2026-08-05T09:28:11.951946403Z",
            "sha256": "12e7845e4bb220b88c2e8311b54d793df2466b079a49f97ce419638a292d01ca",
            "modified_time": "2026-08-05T08:51:40Z",
            "source": "amazon-inspector",
            "versions": [
                "11.3.5"
            ]
        },
        {
            "id": "IN-MAL-2026-014471",
            "import_time": "2026-08-05T09:28:15.844072785Z",
            "sha256": "a9f7f479a4011300e954f114617cc9d8baba31b4118e2005e751ccdfb8a0c423",
            "modified_time": "2026-08-05T08:55:16Z",
            "source": "amazon-inspector",
            "versions": [
                "11.3.6"
            ]
        },
        {
            "id": "IN-MAL-2026-014469",
            "import_time": "2026-08-05T09:28:15.502699482Z",
            "sha256": "e0f0328d2a94970f9c8fc31bb48e544c58b2f8ff0cf7f7bdf53074e8cbcc0872",
            "versions": [
                "0.0.1"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T08:54:59Z"
        },
        {
            "id": "IN-MAL-2026-014443",
            "import_time": "2026-08-05T09:28:11.623529784Z",
            "sha256": "e7ff4f4ef11d2ff4bbba6d98547a1f6c1e5834739b4943f581e057abb9e313ce",
            "versions": [
                "9.4.10"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T08:51:13Z"
        },
        {
            "id": "IN-MAL-2026-014444",
            "import_time": "2026-08-05T09:28:11.785570297Z",
            "sha256": "ede4da38302a4903717596d371ec4bd7f2770af2c4e75662042843b1e4dc3209",
            "modified_time": "2026-08-05T08:51:24Z",
            "source": "amazon-inspector",
            "versions": [
                "9.4.11"
            ]
        },
        {
            "id": "IN-MAL-2026-014442",
            "import_time": "2026-08-05T09:28:11.50236822Z",
            "sha256": "6b75e50341fc75d830790d1b236e36fc66164a9208e12bd6baf946e688bb5b9b",
            "versions": [
                "9.4.12"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T08:51:04Z"
        },
        {
            "id": "IN-MAL-2026-014449",
            "import_time": "2026-08-05T09:28:12.294661497Z",
            "sha256": "fc8097e6410abb45497888e537570e95df36ef068aeecce67189ac6513054124",
            "modified_time": "2026-08-05T08:52:06Z",
            "source": "amazon-inspector",
            "versions": [
                "9.4.9"
            ]
        },
        {
            "id": "IN-MAL-2026-014445",
            "import_time": "2026-08-05T09:28:11.866231998Z",
            "sha256": "9292b17d7778a95abbffacfef462e6b2036bfaf4edd9425eaa55d119edf63dd4",
            "versions": [
                "9.4.7"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T08:51:33Z"
        },
        {
            "id": "IN-MAL-2026-014448",
            "import_time": "2026-08-05T09:28:12.197837454Z",
            "sha256": "a3e85a2c348630fe72c68f82355ab8e0e8b26f10696692be580f16c1b825d8d9",
            "modified_time": "2026-08-05T08:51:58Z",
            "source": "amazon-inspector",
            "versions": [
                "12.5.2"
            ]
        },
        {
            "id": "IN-MAL-2026-014447",
            "import_time": "2026-08-05T09:28:12.093814176Z",
            "sha256": "a52b30b9dc2cc8d6662ff912308956032f92ab32f19c6a0a08f93c849023b80e",
            "versions": [
                "9.4.8"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T08:51:49Z"
        }
    ]
}
References
Credits

Affected packages

npm / beaver-ui-drawer

Package

Affected ranges

Affected versions

0.*
0.0.1
9.*
9.4.7
9.4.8
9.4.9
9.4.10
9.4.11
9.4.12
11.*
11.3.5
11.3.6
12.*
12.5.2

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "setup.js",
            "tlsh": "81a183210af971384391a5e4d85b4816b19be5533388e9e0f38cb7985f97268d3b39fc",
            "sha256": "27d4e916d68299785e80f50b285fde9173eb934d1e027ea66e35c29575507a4c"
        }
    ],
    "package_integrity": [
        {
            "filename": "beaver-ui-drawer-11.3.5.tgz",
            "hashes": {
                "sha1": "36a483dff5c702f9da5b9a6d2ac76dccd40290b6",
                "sha512_sri": "sha512-/EZG8dtp1ML4xnL5mHvXHrfaKL/RllkaM1oJOecMhn6HeukGEvIMuDqLPV96z3W6eNqsfdRgTZamJmb9w1WLCA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/beaver-ui-drawer/MAL-2026-12144.json"