LWA-2026-11335 confirmed malware

sysdo@1.0.0

Malicious code in sysdo (npm)

T1059.007 · JavaScriptT1059.006 · PythonT1113 · Screen CaptureT1115 · Clipboard DataT1005 · Data from Local SystemT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The package installs a stealth clipboard and screen-capture exfiltration tool disguised as a "system binary configuration tool". On execution it silently installs Python and pip dependencies, then runs a hidden overlay (transparent, withdrawn windows with stealth hotkeys) that continuously monitors the clipboard, captures screenshots, and extracts on-screen text via Windows UI Automation. All captured clipboard text, screenshots, and extracted screen content are POSTed to the remote endpoint hxxps://iq-sec[.]vercel[.]app/api, and AI-generated answers are auto-typed back into the system. A bundled VBScript (start_tool.vbs) launches the tool silently in the background with administrative rights. The clipboard and screen content exfiltrated to the remote server can include credentials, tokens, and other sensitive data.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 05:15 PM
analyzed
Aug 15, 2026, 05:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.