sysdo@1.0.0
Malicious code in sysdo (npm)
Analysis
The package installs a stealth clipboard and screen-capture exfiltration tool disguised as a "system binary configuration tool". On execution it silently installs Python and pip dependencies, then runs a hidden overlay (transparent, withdrawn windows with stealth hotkeys) that continuously monitors the clipboard, captures screenshots, and extracts on-screen text via Windows UI Automation. All captured clipboard text, screenshots, and extracted screen content are POSTed to the remote endpoint hxxps://iq-sec[.]vercel[.]app/api, and AI-generated answers are auto-typed back into the system. A bundled VBScript (start_tool.vbs) launches the tool silently in the background with administrative rights. The clipboard and screen content exfiltrated to the remote server can include credentials, tokens, and other sensitive data.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 05:15 PM
- analyzed
- Aug 15, 2026, 05:16 PM
Related advisories
- core-js-buffer@1.0.0
- @ethers-js/contracts@6.9.0
- n8n-nodes-devops-utils@1.0.0
- txs-runner-lib@1.0.1
- txs-random-lib@1.0.1
- txs-builder@1.0.6
- node-fetch-utils@1.2.1
- anthropic-claude-latest@4.7.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.