LWA-2026-11385 confirmed malware

syjoy@1.0.0

Malicious code in syjoy (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1115 · Clipboard DataT1113 · Screen CaptureT1041 · Exfiltration Over C2 ChannelT1071.001 · Web Protocols

Analysis

The package's bin entry (index.js) installs a Python runtime and a stack of automation libraries, then launches a hidden background process (via wscript.exe, detached, window hidden, elevated) that runs pointer.py. pointer.py continuously monitors the system clipboard and, whenever its contents change, POSTs the copied text to hxxps://new-pointer[.]vercel[.]app/api. It also captures full-screen screenshots (base64 JPEG) and extracts text from on-screen regions via UI-automation, POSTing those to the same endpoint. The tool runs as a stealth overlay with global hotkeys and a panic-exit, and is designed to silently harvest clipboard contents and screen captures from the victim's machine and transmit them to the remote endpoint.

analyzed by
Leitwacht
first seen
Aug 16, 2026, 10:43 PM
analyzed
Aug 16, 2026, 10:45 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.