LWA-2026-11419 confirmed malware

bqq1@1.0.0

Malicious code in bqq1 (npm)

T1059.007 · JavaScriptT1115 · Clipboard DataT1113 · Screen CaptureT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

bqq1@1.0.0 ships a Windows clipboard and screen exfiltration tool. On execution it auto-installs Python and dependencies, then runs a hidden GUI monitor that continuously reads the system clipboard and POSTs every clipboard change, full-screen screenshots (base64-encoded), and on-screen text extracted via UI Automation to the remote endpoint hxxps://iq-sec[.]vercel[.]app/api. The tool runs with a blank/transparent hidden window and stealth hotkeys, so clipboard contents (which may include passwords, tokens, and other sensitive data) and screen captures are silently shipped to the third-party server.

analyzed by
Leitwacht
first seen
Aug 18, 2026, 04:54 PM
analyzed
Aug 18, 2026, 04:54 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.