MAL-2026-10428

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sysb1/MAL-2026-10428.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10428
Published
2026-07-13T08:10:57Z
Modified
2026-08-19T03:00:15Z
Summary
Malicious code in sysb1 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (530efe2fec0ffeabda93aa5e9718161f131bb28d35f28432d5d2c2da6e4763a4)

The npm package sysb1 advertises itself as a 'System binary configuration tool' but ships a Windows surveillance agent. index.js (declared as both main and bin) runs at load/start and silently installs the CPython 3.12 runtime via winget, falling back to downloading python-3.12.3-amd64.exe from python.org into the temp directory and running it with /quiet InstallAllUsers=0 PrependPath=1, then silently pip-installs surveillance libraries (keyboard, pyautogui, mss, uiautomation, pyperclip). It then spawns wscript.exe on start_tool.vbs detached and hidden; start_tool.vbs uses ShellExecute with the 'runas' verb and window state 0 to launch 'python pointer.py' as Administrator with no visible window. pointer.py captures clipboard content (pyperclip.paste), screenshots (ImageGrab, mss), and UI/accessibility text (uiautomation), and POSTs the collected data via requests.Session to a hardcoded endpoint https://iq-overlay-pointer.vercel.app/api that the installer did not configure. pointer.py also registers global keyboard hotkey hooks (keyboard.add_hotkey) that drive clipboard reads, screen OCR, keystroke injection (pyautogui.press), and network POSTs, running inside hidden overrideredirect/transparent-color Tk windows with a 'panic_exit' hotkey. Package metadata and identifiers ('IQPointer', 'ULTRA GHOST MODE', 'HACK 1/HACK 2', empty window titles) contradict the stated purpose and are a cover story.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-009863",
            "import_time": "2026-07-13T09:10:56.016202745Z",
            "modified_time": "2026-07-13T08:10:57Z",
            "sha256": "95e8cd8412bd88621ce6b01197ff69e0dc347d017175fcbfe378cdc036407e27",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-010950",
            "import_time": "2026-07-28T14:20:00.972282697Z",
            "modified_time": "2026-07-28T13:40:44Z",
            "sha256": "11f3fe2845ee2a07bcb82ebc43e8e28bdc4e35a96eee4bc2a82ac96c680807ea",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-010942",
            "import_time": "2026-07-28T14:20:00.299051627Z",
            "modified_time": "2026-07-28T13:39:41Z",
            "sha256": "c8f32dffecdfce99c809df1dcd7d18d75cdab188d294e4b67c901e4916e89966",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-017645",
            "import_time": "2026-08-13T17:24:45.807833456Z",
            "modified_time": "2026-08-13T17:17:15Z",
            "sha256": "530efe2fec0ffeabda93aa5e9718161f131bb28d35f28432d5d2c2da6e4763a4",
            "source": "amazon-inspector",
            "versions": [
                "1.0.4"
            ]
        },
        {
            "id": "IN-MAL-2026-018305",
            "import_time": "2026-08-19T02:57:22.605974205Z",
            "modified_time": "2026-08-19T02:50:27Z",
            "sha256": "6a81e81943d977a2c824a28ebbf6b78be0d78656f0dae96367f175d7fca5856b",
            "source": "amazon-inspector",
            "versions": [
                "1.0.5"
            ]
        },
        {
            "id": "IN-MAL-2026-018310",
            "import_time": "2026-08-19T02:57:23.07809155Z",
            "modified_time": "2026-08-19T02:51:09Z",
            "sha256": "9b98909d13a2ac5f3f00667317f85fc354009d43538a10bc0f9023bc443b17a6",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / sysb1

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "pointer.py",
            "sha256": "a095aa6a4b08da23c6f2267bc18fe5f47342a3fa3225309796f54e1935f43207",
            "tlsh": "4af22e09ec1d089ac073cd2f5952a853ff1a07439a5eda17f8bc99901f743468ae4ef9"
        },
        {
            "path": "index.js",
            "sha256": "6044ff1e5d1929c7e31b6e77a4c000ae9400229fbd5733821f88fd2bad8f4cea",
            "tlsh": "de8150075a95a234ed7247a99b07212be517a073b100e69cbcbe83840f76945c073fee"
        },
        {
            "path": "package.json",
            "sha256": "139c49539ac589af5ba968636afa7ab26d48e8329bd119f40f96e3c8dc025731",
            "tlsh": "7ce04f3399615c9344b58aa29a368a05b5718b3f00254c0f31bb511c97a29a245bbb5c"
        }
    ],
    "package_integrity": [
        {
            "filename": "sysb1-1.0.0.tgz",
            "hashes": {
                "sha1": "b4f01fdae03300e650abc68fb08988f6dc79d6ed",
                "sha512_sri": "sha512-1CCAnieozV/7MSJ8BwTTmNK2hPScUQa9rDzqdamzfdgJSQFvaOoxeI/9Y1I/Wqm+kDzKhE6i/ZYus4d2Jf4tew=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sysb1/MAL-2026-10428.json"