beaver-ui-form@12.6.1
Malicious code in beaver-ui-form (npm)
Analysis
The package pretends to be a UI form component but its postinstall hook (node setup.js) downloads and executes platform-specific binaries. It fingerprints the operating system and architecture, then downloads a binary from Cloudflare Workers subdomains (oob-worker[.]cf) or via DNS TXT records from well1[.]site. The downloaded binary is written to /var/tmp/.cache_<hex> on Linux/macOS or %TEMP%\dotnet_diag_<hex>.exe on Windows, then launched as a detached background process. The package also attempts to load the same dropper when imported via require(). A large decoy telemetry.js file pads the package to appear legitimate.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 01:04 PM
- analyzed
- Aug 1, 2026, 01:05 PM
Related advisories
- beaver-ui-form-modal@12.7.6
- beaver-ui-header@12.3.9
- beaver-ui-grid@12.7.3
- beaver-ui-layout@12.9.6
- arbocrate-sla-prober-arbocrate-sla-prober-core@7.5.8
- afisha-storybook-default@9.7.10
- beaver-ui-card-large@9.6.3
- accounts-loading-state@8.9.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.