beaver-ui-actions-button@5.4.7
Malicious code in beaver-ui-actions-button (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1106 · Native APIT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1036.005 · Match Legitimate Resource Name or Location
Analysis
beaver-ui-actions-button masquerades as a React UI component but is a remote binary downloader. On require(), it collects a host fingerprint (hostname, username, cwd, Node.js version, PID) and downloads a platform-specific binary from attacker-controlled infrastructure (oob-worker[.]cf, *.well1[.]site). The binary is written to /var/tmp with a random name, made executable, and spawned as a detached process. Supported platforms: linux x64/arm64, macOS, Windows. The package has no repository, no React dependency, and no actual component code.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 11:16 AM
- analyzed
- Aug 1, 2026, 11:19 AM
- weekly installs
- 116
Related advisories
- snavbox@1.0.1
- bnpl-blocks-mobile-bnpl-faq@35.5.3
- dolyame-ui-filter@35.5.3
- devplatform-spa-plugin-notifier@35.5.7
- fdd41@1.0.0
- axios-native@1.16.3
- @immobiliarelabs/backstage-plugin-gitlab-backend@3.0.3
- @immobiliarelabs/backstage-plugin-gitlab-backend@4.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.