Malicious code in gfff5 (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (2f12f82dc8c54282b428617c03537a54f3361841b02233b6626eae6f1e8ec4ee) gfff5 advertises itself as a 'System binary configuration tool' but its actual behavior is covert surveillance. When the CLI is invoked, index.js silently installs Python 3.12 on Windows (via winget, or by downloading the python.org installer to %TEMP% and running it with `/quiet InstallAllUsers=0 PrependPath=1`), then pip-installs the libraries required by a bundled pointer.py. pointer.py registers global low-level keyboard hooks via the `keyboard` module (including a raw `mash_hook`), captures screenshots with mss / ImageGrab, reads clipboard contents via pyperclip, walks other application windows' UI trees with uiautomation.WalkControl, and POSTs the collected text and images to the hardcoded author endpoint https://iq-sec.vercel.app/api. Stealth features (blank window titles, transparent overlay, a `panic_exit` hotkey, and source comments labeling the installer 'GHOST INSTALLER — No UI, No Admin Popup') confirm the behavior is intentionally hidden from the user and unrelated to the package's declared purpose.
Malicious code in gfff5 (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (2f12f82dc8c54282b428617c03537a54f3361841b02233b6626eae6f1e8ec4ee) gfff5 advertises itself as a 'System binary configuration tool' but its actual behavior is covert surveillance. When the CLI is invoked, index.js silently installs Python 3.12 on Windows (via winget, or by downloading the python.org installer to %TEMP% and running it with `/quiet InstallAllUsers=0 PrependPath=1`), then pip-installs the libraries required by a bundled pointer.py. pointer.py registers global low-level keyboard hooks via the `keyboard` module (including a raw `mash_hook`), captures screenshots with mss / ImageGrab, reads clipboard contents via pyperclip, walks other application windows' UI trees with uiautomation.WalkControl, and POSTs the collected text and images to the hardcoded author endpoint https://iq-sec.vercel.app/api. Stealth features (blank window titles, transparent overlay, a `panic_exit` hotkey, and source comments labeling the installer 'GHOST INSTALLER — No UI, No Admin Popup') confirm the behavior is intentionally hidden from the user and unrelated to the package's declared purpose.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14296
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a85b4a6acd9273b492507dd
Added to database: 08/19/2026, 13:50:30 UTC
Last updated: 08/19/2026, 13:51:31 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.