Malicious code in sysb1 (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (530efe2fec0ffeabda93aa5e9718161f131bb28d35f28432d5d2c2da6e4763a4) The npm package sysb1 advertises itself as a 'System binary configuration tool' but ships a Windows surveillance agent. index.js (declared as both main and bin) runs at load/start and silently installs the CPython 3.12 runtime via winget, falling back to downloading python-3.12.3-amd64.exe from python.org into the temp directory and running it with /quiet InstallAllUsers=0 PrependPath=1, then silently pip-installs surveillance libraries (keyboard, pyautogui, mss, uiautomation, pyperclip). It then spawns wscript.exe on start_tool.vbs detached and hidden; start_tool.vbs uses ShellExecute with the 'runas' verb and window state 0 to launch 'python pointer.py' as Administrator with no visible window. pointer.py captures clipboard content (pyperclip.paste), screenshots (ImageGrab, mss), and UI/accessibility text (uiautomation), and POSTs the collected data via requests.Session to a hardcoded endpoint https://iq-overlay-pointer.vercel.app/api that the installer did not configure. pointer.py also registers global keyboard hotkey hooks (keyboard.add_hotkey) that drive clipboard reads, screen OCR, keystroke injection (pyautogui.press), and network POSTs, running inside hidden overrideredirect/transparent-color Tk windows with a 'panic_exit' hotkey. Package metadata and identifiers ('IQPointer', 'ULTRA GHOST MODE', 'HACK 1/HACK 2', empty window titles) contradict the stated purpose and are a cover story.
Malicious code in sysb1 (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (530efe2fec0ffeabda93aa5e9718161f131bb28d35f28432d5d2c2da6e4763a4) The npm package sysb1 advertises itself as a 'System binary configuration tool' but ships a Windows surveillance agent. index.js (declared as both main and bin) runs at load/start and silently installs the CPython 3.12 runtime via winget, falling back to downloading python-3.12.3-amd64.exe from python.org into the temp directory and running it with /quiet InstallAllUsers=0 PrependPath=1, then silently pip-installs surveillance libraries (keyboard, pyautogui, mss, uiautomation, pyperclip). It then spawns wscript.exe on start_tool.vbs detached and hidden; start_tool.vbs uses ShellExecute with the 'runas' verb and window state 0 to launch 'python pointer.py' as Administrator with no visible window. pointer.py captures clipboard content (pyperclip.paste), screenshots (ImageGrab, mss), and UI/accessibility text (uiautomation), and POSTs the collected data via requests.Session to a hardcoded endpoint https://iq-overlay-pointer.vercel.app/api that the installer did not configure. pointer.py also registers global keyboard hotkey hooks (keyboard.add_hotkey) that drive clipboard reads, screen OCR, keystroke injection (pyautogui.press), and network POSTs, running inside hidden overrideredirect/transparent-color Tk windows with a 'panic_exit' hotkey. Package metadata and identifiers ('IQPointer', 'ULTRA GHOST MODE', 'HACK 1/HACK 2', empty window titles) contradict the stated purpose and are a cover story.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10428
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a85b4c7acd9273b49252837
Added to database: 08/19/2026, 13:51:03 UTC
Last updated: 08/19/2026, 13:51:35 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.