Skip to main content

Malicious code in sysb1 (npm)

0
Critical
Published: 07/13/2026 (07/13/2026, 08:10:57 UTC)
Source: GCVE Database
Product: sysb1

Description

The npm package sysb1, which claims to be a system binary configuration tool, contains malicious code that installs a Windows surveillance agent. Upon loading, it silently installs the CPython 3.12 runtime and several surveillance-related Python libraries. It then runs a hidden Python script with administrator privileges that captures clipboard data, screenshots, UI text, and sends this information to a hardcoded remote server. The package also registers global keyboard hotkeys to perform further data collection and keystroke injection, all while running hidden windows. The package metadata contains suspicious identifiers that contradict its stated purpose.

Affected software

npmghsa
sysb1
Affected versions
=1.0.0=1.0.2=1.0.1=1.0.4=1.0.5=1.0.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 14:38:30 UTC

Technical Analysis

The sysb1 npm package versions 1.0.0 through 1.0.5 include malicious functionality that installs a surveillance agent on Windows systems. The main script installs CPython 3.12 silently via winget or direct download, then installs Python libraries for keyboard and screen monitoring. It executes a hidden Visual Basic script to launch a Python script with administrator privileges. This Python script collects clipboard contents, screenshots, and UI accessibility text, then exfiltrates the data to a hardcoded endpoint. It also sets global keyboard hotkeys to automate data capture and keystroke injection, running in invisible windows with 'panic_exit' hotkeys. The package metadata contains misleading and suspicious identifiers, indicating a cover story for malicious intent.

Potential Impact

Systems running affected versions of the sysb1 package are subject to unauthorized surveillance, including clipboard data capture, screenshot taking, UI text extraction, and keystroke injection. Sensitive information can be exfiltrated to a remote server without user consent. The malware runs with elevated privileges, increasing the potential impact on system confidentiality and integrity.

Mitigation Recommendations

No official patch or remediation is currently documented for this malicious package. Users should immediately uninstall all versions of sysb1 (1.0.0 through 1.0.5) and avoid installing packages from untrusted sources. Monitor for and remove any installed Python runtimes and surveillance libraries associated with this package. Since this is a malicious package rather than a traditional vulnerability, remediation involves removal and blocking of the package rather than patching. Check vendor or repository advisories for updates or takedown notices.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-10428
Osv Schema Version
1.7.4
Ecosystems
["npm"]

Threat ID: 6a85b4c7acd9273b49252837

Added to database: 08/19/2026, 13:51:03 UTC

Last enriched: 08/19/2026, 14:38:30 UTC

Last updated: 10/02/2026, 13:52:28 UTC

Views: 27

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses