Malicious code in sysb1 (npm)
Description
The npm package sysb1, which claims to be a system binary configuration tool, contains malicious code that installs a Windows surveillance agent. Upon loading, it silently installs the CPython 3.12 runtime and several surveillance-related Python libraries. It then runs a hidden Python script with administrator privileges that captures clipboard data, screenshots, UI text, and sends this information to a hardcoded remote server. The package also registers global keyboard hotkeys to perform further data collection and keystroke injection, all while running hidden windows. The package metadata contains suspicious identifiers that contradict its stated purpose.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The sysb1 npm package versions 1.0.0 through 1.0.5 include malicious functionality that installs a surveillance agent on Windows systems. The main script installs CPython 3.12 silently via winget or direct download, then installs Python libraries for keyboard and screen monitoring. It executes a hidden Visual Basic script to launch a Python script with administrator privileges. This Python script collects clipboard contents, screenshots, and UI accessibility text, then exfiltrates the data to a hardcoded endpoint. It also sets global keyboard hotkeys to automate data capture and keystroke injection, running in invisible windows with 'panic_exit' hotkeys. The package metadata contains misleading and suspicious identifiers, indicating a cover story for malicious intent.
Potential Impact
Systems running affected versions of the sysb1 package are subject to unauthorized surveillance, including clipboard data capture, screenshot taking, UI text extraction, and keystroke injection. Sensitive information can be exfiltrated to a remote server without user consent. The malware runs with elevated privileges, increasing the potential impact on system confidentiality and integrity.
Mitigation Recommendations
No official patch or remediation is currently documented for this malicious package. Users should immediately uninstall all versions of sysb1 (1.0.0 through 1.0.5) and avoid installing packages from untrusted sources. Monitor for and remove any installed Python runtimes and surveillance libraries associated with this package. Since this is a malicious package rather than a traditional vulnerability, remediation involves removal and blocking of the package rather than patching. Check vendor or repository advisories for updates or takedown notices.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10428
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a85b4c7acd9273b49252837
Added to database: 08/19/2026, 13:51:03 UTC
Last enriched: 08/19/2026, 14:38:30 UTC
Last updated: 10/02/2026, 13:52:28 UTC
Views: 27
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.