beaver-ui-side-navigation @35.7.1
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 11:52 AM UTC
OSV ID
MAL-2026-12823
Ecosystem
npm
Summary
On require()/import of the package, index.js unconditionally loads _helpers.js which fetches a platform-specific binary from attacker-controlled Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf100-416.workers.dev, oob-worker.cf101-adf.workers.dev) with DNS-TXT-based fallback via *.dl.wel1.ru subdomains. Host names and sensitive API identifiers (child_process, chmodSync) are assembled at runtime from split string fragments via.join("") to evade static detection. The fetched opaque binary is written to /tmp or %TEMP% under cover names (.cache_<rand> on Unix, dotnet_diag_<rand>.exe on Windows), chmod 0755'd, and spawned detached via /bin/sh -c or cmd.exe with no hash or signature verification. A cover-story telemetry framing (DISABLE_TELEMETRY / ANALYTICS_OPT_OUT / DO_NOT_TRACK env checks,.analytics_state marker file) accompanies the dropper. lib/telemetry.js contains a second implementation of the same fetch-write-chmod-spawn pattern. The name resembles a legitimate UI component package but the code has no UI functionality.
Source: amazon-inspector (868e87654c2af06a8362918fbcd52680c253a85063f1a0c7fc71494b0cfd304d)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.