bqq1@1.0.0
Malicious code in bqq1 (npm)
Analysis
bqq1@1.0.0 ships a Windows clipboard and screen exfiltration tool. On execution it auto-installs Python and dependencies, then runs a hidden GUI monitor that continuously reads the system clipboard and POSTs every clipboard change, full-screen screenshots (base64-encoded), and on-screen text extracted via UI Automation to the remote endpoint hxxps://iq-sec[.]vercel[.]app/api. The tool runs with a blank/transparent hidden window and stealth hotkeys, so clipboard contents (which may include passwords, tokens, and other sensitive data) and screen captures are silently shipped to the third-party server.
- analyzed by
- Leitwacht
- first seen
- Aug 18, 2026, 04:54 PM
- analyzed
- Aug 18, 2026, 04:54 PM
Related advisories
- syjoy@1.0.0
- sysdo@1.0.0
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- ts-eslint-jest@1.0.0
- jest-formatter@1.0.0
- express-mongo-limit@2.0.1
- pinokio-redis@1.0.127
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.