Hostile 100% javascript Download

beaver-ui-form-object 12.1.7

Downloads and executes remote binary

Library import stages and detaches a fetched executablenpm entry import conceals a native payload sidecar

Also flagged by osv (MAL-2026-12145: Malicious code in beaver-ui-form-object (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.