beaver-ui-layout@12.9.6
Malicious code in beaver-ui-layout (npm)
Analysis
beaver-ui-layout@12.9.6 is a trojanized package impersonating a UI layout library. Its postinstall hook runs setup.js, which fingerprints the system (OS, architecture), then downloads a platform-specific binary payload from obfuscated C2 hosts (oob-worker[.]cf subdomains — 99-9b3[.]workers[.]dev, 100-416[.]workers[.]dev, 101-adf[.]workers[.]dev, 102-baf[.]workers[.]dev, 103-070[.]workers[.]dev) with DNS TXT fallback domains (tin[.]dl[.]well1[.]site, tina[.]dl[.]well1[.]site, ldr[.]dl[.]well1[.]site, win[.]dl[.]well1[.]site). The downloaded binary is written to /var/tmp/.cache_<hex> (Linux/macOS) or %TEMP%\dotnet_diag_<hex>.exe (Windows) and executed as a detached background process. A 6-hour stamp file prevents repeated downloads. The package ships a large decoy telemetry.js file to appear legitimate.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 01:04 PM
- analyzed
- Aug 1, 2026, 01:05 PM
Related advisories
- arbocrate-sla-prober-arbocrate-sla-prober-core@7.5.8
- afisha-storybook-default@9.7.10
- beaver-ui-card-large@9.6.3
- accounts-loading-state@8.9.4
- bcore-bravo-eslint-config@9.5.7
- accounts-timeline@9.6.10
- a.poltoradnev-package-c@6.1.10
- warp-drive-internal-tooling@99.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.