MAL-2026-13522

    Dashboard / Malicious Package / MAL-2026-13522

    MAL-2026-13522

    Published: 7 Aug 2026Last Modified: 18 Aug 2026

    Summary: Malicious code in base-ui-cli (npm)

    Details: Source: amazon-inspector (6bd7a855915fc307b9d0c8feee91b135ea2724c300205df6fd3dcb32833ee95b) dist/index.js issues fetch() calls to https://base-ui-pro-registry.l-dimitrov.workers.dev in addition to https://registry.npmjs.org. The Cloudflare Workers host is controlled by an individual (l-dimitrov.workers.dev) rather than any official registry or vendor infrastructure, and the package name 'base-ui-cli' evokes the unrelated Base UI component library, suggesting a lookalike/imposter shape. Routing package-manager-adjacent traffic through an author-controlled proxy that mirrors registry.npmjs.org creates a channel for delivering attacker-substituted package content or credential-bearing requests to a third-party host.

    Affected packages

    Package

    Name: base-ui-cli

    Purl: pkg:npm/base-ui-cli

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.1.47
    MAL-2026-13522 | CVE-DB