LWA-2026-7347 MAL-2026-12034 ↗ confirmed malware

beaver-ui-form-modal@12.7.6

Malicious code in beaver-ui-form-modal (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1568.002 · DNS CalculationT1204.002 · Malicious File

Analysis

beaver-ui-form-modal@12.7.6 is a trojanized package impersonating a React UI component. The postinstall hook runs setup.js, which downloads a platform-specific binary from obfuscated C2 hosts (oob-worker[.]cf and workers[.]dev subdomains) with a DNS TXT record fallback channel. The downloaded binary is written to /var/tmp/.cache_<hex> on Linux/macOS or C:\Windows\Temp\dotnet_diag_<hex>.exe on Windows, made executable, and launched as a detached background process. The package contains no actual UI code — index.js is a 538-byte stub. C2 hosts observed: oob-worker[.]cf, workers[.]dev. DNS fallback domains: tin[.]dl[.]well1[.]site, tina[.]dl[.]well1[.]site, ldr[.]dl[.]well1[.]site, win[.]dl[.]well1[.]site.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 01:04 PM
analyzed
Aug 1, 2026, 01:05 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.