-= Per source details. Do not edit below this line.=-
Despite a README describing a 'Windows diagnostic utility,' the package implements an anti-proctoring overlay for cheating on remote exams (Safe Exam Browser / AMCAT). main.js drives an Electron window hidden from screen capture via SetWindowDisplayAffinity(WDA_EXCLUDEFROMCAPTURE) and WS_EX_TOOLWINDOW/NOACTIVATE, launched as a detached process renamed to 'SearchApp.exe' to masquerade as Windows Search, and polls for a proctoring process 'core.exe' via tasklist /FI "IMAGENAME eq core.exe" to temporarily normalize the affinity flag while the proctor scans. bin/kalamasha-tool.js spawns a 'Ghost Watchdog' that copies node_modules/electron/dist/electron.exe to SearchApp.exe and immortally respawns it with backoff when killed, logging to %LOCALAPPDATA%\Microsoft\Windows\Diagnostics\boot.log. bin/chrome_cookies.ps1 walks Chrome/Edge/Brave 'User Data' profile directories, copies the locked Cookies SQLite DB to %TEMP%, reads the DPAPI-wrapped os_crypt.encrypted_key from Local State, and AES-256-GCM-decrypts cookie values for openai.com, chatgpt.com, auth0.openai.com and auth.openai.com; the decrypted cookies are injected into an embedded Electron session to drive those AI services under the browser owner's identity. main.js captures the foreground exam window (screenshot plus UI-Automation text extraction) and posts the content to https://ipc.shadxino.internal via HTTP POST from lines 364 and 368. The tarball also ships a 27MB opaque bin/uia_extract.exe alongside a Python source equivalent, invoked as python "${pyPath}" || "${exePath}".
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020342",
"import_time": "2026-09-23T02:46:21.8083142Z",
"modified_time": "2026-09-23T02:44:31Z",
"sha256": "76b05c7a5581562edc719cbaaf2f6b317d322a6a2ef96c9fc905b53394e42101",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "main.js",
"sha256": "23b15a5a2d9fcea02a14d66e8c04f7d46cb38a04b3e6bfd55705f14ade8944b5",
"tlsh": "0983d75a606511318433af758b3b6d16f726a523e0419354beacc3d82fb1419ceb2fee"
},
{
"path": "bin/chrome_cookies.ps1",
"sha256": "21b61ec810331850d72423c40c5448e6cd310c4cfad6aed54f92cd7e7cac5f3a",
"tlsh": "1c3264a67812514c10f15f39e9f698a8f91e9027d1e60918fddcc4e01f7046adef8f69"
},
{
"path": "bin/kalamasha-tool.js",
"sha256": "0c293be90c10c8a7618d25f4c4811fa63612b7bc5199b86e10bb31eb36c716dd",
"tlsh": "eee121499267233499b15fea57321c1adb2b9123d5446344b89c83ca3f3642ccdb6fee"
}
],
"package_integrity": [
{
"filename": "moidevl-1.0.0.tgz",
"hashes": {
"sha1": "2b6e945f59d46aee9d05ff151321c650eec34562",
"sha512_sri": "sha512-Yxd+ZqWt8G8ENCeE827PVgRnNqzo7vtR/W2xycLRu6XMXo/Y3k4WZiluBpqstsHfGu6Jp4Dm64KQg343PUKoyw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/moidevl/MAL-2026-16441.json"