Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in beautiful-ui-monitoring (npm)

0
High
Published: 08/06/2026 (08/06/2026, 13:11:08 UTC)
Source: GCVE Database
Product: beautiful-ui-monitoring

Description

The npm package beautiful-ui-monitoring version 1.0.8 is a malicious package that falsely advertises itself as a UI design tool but contains no UI code. Instead, its postinstall script compiles a native shared library to a world-writable temporary directory. This library, when loaded, deletes all shared object files (*.so) under /tmp and logs the current user and group IDs to a file. The package author field is empty, and the package includes test code demonstrating the malicious behavior. Installing this package results in planting a destructive native artifact in a shared location under misleading pretenses.

Affected software

npmghsa
beautiful-ui-monitoring
Affected versions
=1.0.8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 18:39:53 UTC

Technical Analysis

The beautiful-ui-monitoring npm package version 1.0.8 contains malicious code embedded in its postinstall script. Rather than providing UI functionality, it compiles a C source file into a shared library at /tmp/monitoring.so, a world-writable location. This shared library uses a constructor attribute to execute code upon loading that unlinks (deletes) all *.so files in /tmp and writes the current UID and GID to /tmp/monitoring.log. The package includes test scripts that load this library via LD_PRELOAD and dlopen, demonstrating the intended destructive trigger. The package author is unspecified, and the package does not implement its advertised UI features, indicating deliberate deception and malicious intent.

Potential Impact

Installation of this package results in the creation and potential loading of a native shared library that deletes shared object files in the /tmp directory, which could disrupt other processes relying on those files. The malicious code also logs user and group IDs, potentially aiding further malicious activity. The destructive behavior affects the shared temporary directory, which is world-writable and commonly used by many applications, potentially causing denial of service or instability on the affected system.

Mitigation Recommendations

No official patch or remediation is currently available for this package. The best mitigation is to avoid installing [email protected] and remove it if already installed. Since this is a malicious package, users should rely on trusted sources and verify package authenticity before installation. Monitor and clean the /tmp directory for any residual malicious artifacts such as monitoring.so or monitoring.log. Consider using package integrity verification tools and restricting write permissions to /tmp where feasible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13422
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a74cf8ebf8831d5391aea3f

Added to database: 08/06/2026, 18:16:46 UTC

Last enriched: 08/06/2026, 18:39:53 UTC

Last updated: 08/06/2026, 18:39:53 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses