Malicious code in syjoy (npm)
Description
The npm package syjoy version 1.0.0 masquerades as a system binary configuration tool but contains malicious Python code that harvests user data and enables remote control of the host. On first run, it silently installs Python 3.12 and executes a Python script that captures keystrokes, clipboard data, screenshots, and extracts text from other application windows. The stolen data is sent to a hardcoded remote server, which can respond with commands that are automatically typed into the active window, effectively allowing remote input injection. The package uses hidden windows and elevated privileges to evade detection. This behavior indicates the package is a covert tool likely intended for unauthorized data collection and remote manipulation rather than legitimate configuration management.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The npm package syjoy (version 1.0.0) contains a malicious payload implemented in Python (pointer.py) that is installed and executed silently upon first use. The payload installs Python 3.12 if not present, runs with elevated privileges and hidden windows, and performs extensive data harvesting including global keyboard hooks, clipboard reading, screenshots, and UI Automation tree traversal to extract text from arbitrary windows. Harvested data is exfiltrated to a hardcoded endpoint (https://new-pointer.vercel.app/api). The remote server can send back commands that are injected as keyboard input into the host system, enabling remote control. The package's user interface is designed to be invisible and obfuscates window titles. Internal mode names suggest the tool is intended for covert assessments or cheating overlays rather than legitimate system configuration.
Potential Impact
This malicious package compromises user privacy by harvesting sensitive data such as keystrokes, clipboard contents, screenshots, and application text. It also enables remote attackers to inject arbitrary keyboard input into the victim's system, potentially allowing unauthorized actions or manipulation of applications. The silent installation of Python and use of elevated privileges increase the risk of undetected persistence and control. This can lead to data leakage, unauthorized system control, and potential further compromise of the host environment.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately uninstall the syjoy package version 1.0.0 and avoid installing it. Since the package installs Python silently and runs hidden scripts, affected systems should be scanned for the presence of the Python payload (pointer.py) and any related artifacts such as start_tool.vbs. Network monitoring for connections to https://new-pointer.vercel.app/api may help detect compromise. Consider restricting npm package sources to trusted repositories and auditing dependencies before installation. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-14213
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4c7acd9273b4925284f
Added to database: 08/19/2026, 13:51:03 UTC
Last enriched: 08/19/2026, 14:40:02 UTC
Last updated: 10/02/2026, 13:52:33 UTC
Views: 29
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.