Malicious code in beautiful-ui-monitoring (npm)
The npm package beautiful-ui-monitoring version 1.0.8 is a malicious package that falsely advertises itself as a UI design tool but contains no UI code. Instead, its postinstall script compiles a native shared library to a world-writable temporary directory. This library, when loaded, deletes all shared object files (*.so) under /tmp and logs the current user and group IDs to a file. The package author field is empty, and the package includes test code demonstrating the malicious behavior. Installing this package results in planting a destructive native artifact in a shared location under misleading pretenses.
AI Analysis
Technical Summary
The beautiful-ui-monitoring npm package version 1.0.8 contains malicious code embedded in its postinstall script. Rather than providing UI functionality, it compiles a C source file into a shared library at /tmp/monitoring.so, a world-writable location. This shared library uses a constructor attribute to execute code upon loading that unlinks (deletes) all *.so files in /tmp and writes the current UID and GID to /tmp/monitoring.log. The package includes test scripts that load this library via LD_PRELOAD and dlopen, demonstrating the intended destructive trigger. The package author is unspecified, and the package does not implement its advertised UI features, indicating deliberate deception and malicious intent.
Potential Impact
Installation of this package results in the creation and potential loading of a native shared library that deletes shared object files in the /tmp directory, which could disrupt other processes relying on those files. The malicious code also logs user and group IDs, potentially aiding further malicious activity. The destructive behavior affects the shared temporary directory, which is world-writable and commonly used by many applications, potentially causing denial of service or instability on the affected system.
Mitigation Recommendations
No official patch or remediation is currently available for this package. The best mitigation is to avoid installing [email protected] and remove it if already installed. Since this is a malicious package, users should rely on trusted sources and verify package authenticity before installation. Monitor and clean the /tmp directory for any residual malicious artifacts such as monitoring.so or monitoring.log. Consider using package integrity verification tools and restricting write permissions to /tmp where feasible.
Malicious code in beautiful-ui-monitoring (npm)
Description
The npm package beautiful-ui-monitoring version 1.0.8 is a malicious package that falsely advertises itself as a UI design tool but contains no UI code. Instead, its postinstall script compiles a native shared library to a world-writable temporary directory. This library, when loaded, deletes all shared object files (*.so) under /tmp and logs the current user and group IDs to a file. The package author field is empty, and the package includes test code demonstrating the malicious behavior. Installing this package results in planting a destructive native artifact in a shared location under misleading pretenses.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The beautiful-ui-monitoring npm package version 1.0.8 contains malicious code embedded in its postinstall script. Rather than providing UI functionality, it compiles a C source file into a shared library at /tmp/monitoring.so, a world-writable location. This shared library uses a constructor attribute to execute code upon loading that unlinks (deletes) all *.so files in /tmp and writes the current UID and GID to /tmp/monitoring.log. The package includes test scripts that load this library via LD_PRELOAD and dlopen, demonstrating the intended destructive trigger. The package author is unspecified, and the package does not implement its advertised UI features, indicating deliberate deception and malicious intent.
Potential Impact
Installation of this package results in the creation and potential loading of a native shared library that deletes shared object files in the /tmp directory, which could disrupt other processes relying on those files. The malicious code also logs user and group IDs, potentially aiding further malicious activity. The destructive behavior affects the shared temporary directory, which is world-writable and commonly used by many applications, potentially causing denial of service or instability on the affected system.
Mitigation Recommendations
No official patch or remediation is currently available for this package. The best mitigation is to avoid installing [email protected] and remove it if already installed. Since this is a malicious package, users should rely on trusted sources and verify package authenticity before installation. Monitor and clean the /tmp directory for any residual malicious artifacts such as monitoring.so or monitoring.log. Consider using package integrity verification tools and restricting write permissions to /tmp where feasible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13422
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a74cf8ebf8831d5391aea3f
Added to database: 08/06/2026, 18:16:46 UTC
Last enriched: 08/06/2026, 18:39:53 UTC
Last updated: 08/06/2026, 18:39:53 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.