LWA-2026-7345 MAL-2026-11507 ↗ confirmed malware

beaver-ui-grid@12.7.3

Malicious code in beaver-ui-grid (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1204.002 · Malicious FileT1059.003 · Windows Command Shell

Analysis

The postinstall hook (node setup.js || true) downloads and executes a platform-specific binary. It resolves the OS and architecture, then fetches a binary from a shuffled list of Cloudflare Workers subdomains (oob-worker[.]cf with hex-prefixed subdomains such as 99-9b3, 100-416, 101-adf, 102-baf, 103-070) with DNS TXT record fallback from tin[.]dl[.]well1[.]site, tina[.]dl[.]well1[.]site, ldr[.]dl[.]well1[.]site, and win[.]dl[.]well1[.]site. The downloaded binary is written to /var/tmp/.cache_<random hex> (or dotnet_diag_<hex>.exe on Windows), made executable, and launched as a detached background process that outlives the installer. The package contains no actual UI components despite its name and description.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 01:04 PM
analyzed
Aug 1, 2026, 01:05 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.