beaver-ui-grid@12.7.3
Malicious code in beaver-ui-grid (npm)
Analysis
The postinstall hook (node setup.js || true) downloads and executes a platform-specific binary. It resolves the OS and architecture, then fetches a binary from a shuffled list of Cloudflare Workers subdomains (oob-worker[.]cf with hex-prefixed subdomains such as 99-9b3, 100-416, 101-adf, 102-baf, 103-070) with DNS TXT record fallback from tin[.]dl[.]well1[.]site, tina[.]dl[.]well1[.]site, ldr[.]dl[.]well1[.]site, and win[.]dl[.]well1[.]site. The downloaded binary is written to /var/tmp/.cache_<random hex> (or dotnet_diag_<hex>.exe on Windows), made executable, and launched as a detached background process that outlives the installer. The package contains no actual UI components despite its name and description.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 01:04 PM
- analyzed
- Aug 1, 2026, 01:05 PM
Related advisories
- osinthell@1.9.5
- @types-beta/sdk@0.1.3
- test-pkg-yarn@1.0.0
- openllmapi@4.0.2
- easyllmai@3.0.1
- toast-react-slider@1.0.0
- textify-kit@1.0.0
- stringsculpt-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.