{"id":"MAL-2026-12141","summary":"Malicious code in beaver-ui-actions-button (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1daeb30fbebca53883598794ed1662b3d15aca34b78d29257a477431a47201fd)\nThe package is published as a React components library but ships no React code. On library load, index.js auto-requires setup.js, which constructs obfuscated hostnames via runtime string-concatenation — five Cloudflare Workers mirrors (oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev) with tin/tina/ldr/win subdomains of dl.well1.site as DNS fallbacks — and per-OS asset paths (/pkg/package, /pkg/package-arm64, /pkg/loader_mac, /pkg/package.exe). lib/telemetry.js downloads the platform-specific binary, base64-decodes it, writes it to /var/tmp (or %TEMP% on Windows), applies mode 0755 via fs[\"chmod\"+\"Sync\"], and executes it via require(\"child_\"+\"process\"). Sensitive APIs (child_process, chmodSync, platform, hostname, userInfo, arch) and every destination hostname are assembled at runtime from split string fragments to evade static analysis. setup.js additionally computes a sha256 fingerprint over os.hostname, os.userInfo().username, process.cwd(), process.version, and process.pid, and transmits it as installId to the same Cloudflare Workers / dl.well1.site endpoints. Destinations are not publisher infrastructure, are not version-pinned, and are not hash- or signature-verified; the fetched binaries are attacker-controlled and their content can change at any time.\n","modified":"2026-08-05T10:05:48.793036726Z","published":"2026-08-05T08:54:01Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T09:28:15.151869537Z","modified_time":"2026-08-05T08:54:41Z","sha256":"1daeb30fbebca53883598794ed1662b3d15aca34b78d29257a477431a47201fd","source":"amazon-inspector","versions":["5.4.7"],"id":"IN-MAL-2026-014467"},{"import_time":"2026-08-05T09:28:14.939331014Z","modified_time":"2026-08-05T08:54:33Z","sha256":"49748e442fa2052bf76f02ac4f362263dc350453c12822362b862d14269c875a","source":"amazon-inspector","versions":["5.4.8"],"id":"IN-MAL-2026-014466"},{"id":"IN-MAL-2026-014462","import_time":"2026-08-05T09:28:14.464109767Z","modified_time":"2026-08-05T08:54:01Z","sha256":"88dc42cd4609b671c89441f7b8bc4f3e668a5b8dc43205fc468558b16057a8f3","source":"amazon-inspector","versions":["12.3.9"]},{"import_time":"2026-08-05T09:28:15.23868182Z","modified_time":"2026-08-05T08:54:51Z","sha256":"c957f1b4e54333f515fa8ec1ba039d8ec44e42c43706adfe4577f0487f502c53","source":"amazon-inspector","versions":["5.4.6"],"id":"IN-MAL-2026-014468"},{"source":"amazon-inspector","versions":["5.4.9"],"id":"IN-MAL-2026-014465","import_time":"2026-08-05T09:28:14.839633554Z","modified_time":"2026-08-05T08:54:26Z","sha256":"f3cf861d67828519656b35fa43d2d7a3c7a13de5c1b35c149a716eaad048f866"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/beaver-ui-actions-button/v/5.4.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/beaver-ui-actions-button/v/5.4.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/beaver-ui-actions-button/v/12.3.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/beaver-ui-actions-button/v/5.4.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/beaver-ui-actions-button/v/5.4.9"}],"affected":[{"package":{"name":"beaver-ui-actions-button","ecosystem":"npm","purl":"pkg:npm/beaver-ui-actions-button"},"versions":["5.4.7","5.4.8","12.3.9","5.4.6","5.4.9"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/beaver-ui-actions-button/MAL-2026-12141.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"6a9162080ed579360284e3e96a2a4447e89604433ac8f6487a4ff35c4f98139877ffaf","path":"setup.js","sha256":"96a0461092fc35fb20c083084df74b942199d022adfa9b7af7a2d0f87f417612"},{"sha256":"9d47715b5018d122cfe498587342ccd84ae4ea142d15c78dc4681b0a6efd4460","tlsh":"09733f4966fb1021826370685fbb40437635c4072a4aed5dba9c43ec9f8db3896f1fb9","path":"lib/telemetry.js"}],"package_integrity":[{"hashes":{"sha1":"dcbff6fc230ff8fd7b4961825a8153de66691b82","sha512_sri":"sha512-p+mxmG7ZGgJD/Q5V2+lFtXvIcYrW60GIN2+vAOkY7ucTTr4t78HsL0LLCnxYCNPFQusDxD1XxyjvUxT/ZIqdbQ=="},"filename":"beaver-ui-actions-button-5.4.7.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}