{"id":"MAL-2026-13522","summary":"Malicious code in base-ui-cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6bd7a855915fc307b9d0c8feee91b135ea2724c300205df6fd3dcb32833ee95b)\ndist/index.js issues fetch() calls to https://base-ui-pro-registry.l-dimitrov.workers.dev in addition to https://registry.npmjs.org. The Cloudflare Workers host is controlled by an individual (l-dimitrov.workers.dev) rather than any official registry or vendor infrastructure, and the package name 'base-ui-cli' evokes the unrelated Base UI component library, suggesting a lookalike/imposter shape. Routing package-manager-adjacent traffic through an author-controlled proxy that mirrors registry.npmjs.org creates a channel for delivering attacker-substituted package content or credential-bearing requests to a third-party host.\n","modified":"2026-08-18T05:46:19.019949223Z","published":"2026-08-07T12:36:37Z","withdrawn":"2026-08-13T16:18:30.952342Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017050","import_time":"2026-08-07T12:51:23.933560379Z","modified_time":"2026-08-07T12:36:37Z","sha256":"6bd7a855915fc307b9d0c8feee91b135ea2724c300205df6fd3dcb32833ee95b","source":"amazon-inspector","versions":["1.1.47"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/base-ui-cli/v/1.1.47"}],"affected":[{"package":{"name":"base-ui-cli","ecosystem":"npm","purl":"pkg:npm/base-ui-cli"},"versions":["1.1.47"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/base-ui-cli/MAL-2026-13522.json","indicators":{"evidence_files":[{"sha256":"aba30b8d02ffeb11841172abb9d1e3fb9be9d835a2d837318fd7fa9ccd7886ec","tlsh":"31b22a2566d8607b33d921900d79241376b6cda8c505b03da3bdc4af27926ac81fbfb9","path":"dist/index.js"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-2GY/IXr7+h3jfIKu/f2MN2K8LeLHqGLNFmSqZuAI+/0GWgiWOoOrdJnQUWTnHNt2TAhwrQzxPVD4EV+KntmEBQ==","sha1":"65d40cf726ac36839f00e6c80a4c11374ea23af7"},"filename":"base-ui-cli-1.1.47.tgz"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}