syjoy@1.0.0
Malicious code in syjoy (npm)
Analysis
The package's bin entry (index.js) installs a Python runtime and a stack of automation libraries, then launches a hidden background process (via wscript.exe, detached, window hidden, elevated) that runs pointer.py. pointer.py continuously monitors the system clipboard and, whenever its contents change, POSTs the copied text to hxxps://new-pointer[.]vercel[.]app/api. It also captures full-screen screenshots (base64 JPEG) and extracts text from on-screen regions via UI-automation, POSTing those to the same endpoint. The tool runs as a stealth overlay with global hotkeys and a panic-exit, and is designed to silently harvest clipboard contents and screen captures from the victim's machine and transmit them to the remote endpoint.
- analyzed by
- Leitwacht
- first seen
- Aug 16, 2026, 10:43 PM
- analyzed
- Aug 16, 2026, 10:45 PM
Related advisories
- sysdo@1.0.0
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- ts-eslint-jest@1.0.0
- jest-formatter@1.0.0
- express-mongo-limit@2.0.1
- pinokio-redis@1.0.127
- zredis-typed@1.0.127
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.