LWA-2026-7318 MAL-2026-12141 ↗ confirmed malware

beaver-ui-actions-button@5.4.7

Malicious code in beaver-ui-actions-button (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1106 · Native APIT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1036.005 · Match Legitimate Resource Name or Location

Analysis

beaver-ui-actions-button masquerades as a React UI component but is a remote binary downloader. On require(), it collects a host fingerprint (hostname, username, cwd, Node.js version, PID) and downloads a platform-specific binary from attacker-controlled infrastructure (oob-worker[.]cf, *.well1[.]site). The binary is written to /var/tmp with a random name, made executable, and spawned as a detached process. Supported platforms: linux x64/arm64, macOS, Windows. The package has no repository, no React dependency, and no actual component code.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 11:16 AM
analyzed
Aug 1, 2026, 11:19 AM
weekly installs
116

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.