MAL-2026-16441

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/moidevl/MAL-2026-16441.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16441
Published
2026-09-23T02:44:31Z
Modified
2026-09-23T03:00:06Z
Summary
Malicious code in moidevl (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (76b05c7a5581562edc719cbaaf2f6b317d322a6a2ef96c9fc905b53394e42101)

Despite a README describing a 'Windows diagnostic utility,' the package implements an anti-proctoring overlay for cheating on remote exams (Safe Exam Browser / AMCAT). main.js drives an Electron window hidden from screen capture via SetWindowDisplayAffinity(WDA_EXCLUDEFROMCAPTURE) and WS_EX_TOOLWINDOW/NOACTIVATE, launched as a detached process renamed to 'SearchApp.exe' to masquerade as Windows Search, and polls for a proctoring process 'core.exe' via tasklist /FI "IMAGENAME eq core.exe" to temporarily normalize the affinity flag while the proctor scans. bin/kalamasha-tool.js spawns a 'Ghost Watchdog' that copies node_modules/electron/dist/electron.exe to SearchApp.exe and immortally respawns it with backoff when killed, logging to %LOCALAPPDATA%\Microsoft\Windows\Diagnostics\boot.log. bin/chrome_cookies.ps1 walks Chrome/Edge/Brave 'User Data' profile directories, copies the locked Cookies SQLite DB to %TEMP%, reads the DPAPI-wrapped os_crypt.encrypted_key from Local State, and AES-256-GCM-decrypts cookie values for openai.com, chatgpt.com, auth0.openai.com and auth.openai.com; the decrypted cookies are injected into an embedded Electron session to drive those AI services under the browser owner's identity. main.js captures the foreground exam window (screenshot plus UI-Automation text extraction) and posts the content to https://ipc.shadxino.internal via HTTP POST from lines 364 and 368. The tarball also ships a 27MB opaque bin/uia_extract.exe alongside a Python source equivalent, invoked as python "${pyPath}" || "${exePath}".

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020342",
            "import_time":  "2026-09-23T02:46:21.8083142Z",
            "modified_time":  "2026-09-23T02:44:31Z",
            "sha256":  "76b05c7a5581562edc719cbaaf2f6b317d322a6a2ef96c9fc905b53394e42101",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / moidevl

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "main.js",
            "sha256":  "23b15a5a2d9fcea02a14d66e8c04f7d46cb38a04b3e6bfd55705f14ade8944b5",
            "tlsh":  "0983d75a606511318433af758b3b6d16f726a523e0419354beacc3d82fb1419ceb2fee"
        },
        {
            "path":  "bin/chrome_cookies.ps1",
            "sha256":  "21b61ec810331850d72423c40c5448e6cd310c4cfad6aed54f92cd7e7cac5f3a",
            "tlsh":  "1c3264a67812514c10f15f39e9f698a8f91e9027d1e60918fddcc4e01f7046adef8f69"
        },
        {
            "path":  "bin/kalamasha-tool.js",
            "sha256":  "0c293be90c10c8a7618d25f4c4811fa63612b7bc5199b86e10bb31eb36c716dd",
            "tlsh":  "eee121499267233499b15fea57321c1adb2b9123d5446344b89c83ca3f3642ccdb6fee"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "moidevl-1.0.0.tgz",
            "hashes":  {
                "sha1":  "2b6e945f59d46aee9d05ff151321c650eec34562",
                "sha512_sri":  "sha512-Yxd+ZqWt8G8ENCeE827PVgRnNqzo7vtR/W2xycLRu6XMXo/Y3k4WZiluBpqstsHfGu6Jp4Dm64KQg343PUKoyw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/moidevl/MAL-2026-16441.json"