moidevy@1.0.0
Malicious code in moidevy (npm)
Analysis
moidevy@1.0.0 is a Windows proctoring-evasion and exam-cheat tool disguised as a "DOM utility / diagnostic bridge". On launch it copies the bundled Electron binary to a stealth name "SearchApp.exe" and spawns a detached watchdog process that respawns itself every 2-15 seconds when killed, writing a log to %LOCALAPPDATA%\Microsoft\Windows\Diagnostics\boot.log. The Electron app sets the WDA_EXCLUDEFROMCAPTURE window flag and WS_EX_TOOLWINDOW/NOACTIVATE styles to hide its overlay from screen capture and Alt-Tab, actively demotes the proctoring application's window, and toggles its stealth flag off when it detects the proctor's core.exe process. It extracts on-screen exam text via Windows UI Automation (bin/uia_extract.py / uia_extract.exe) and PowerShell screen capture (bin/stealth_capture.ps1). It also ships bin/chrome_cookies.ps1, which decrypts Chrome, Edge, and Brave cookies for openai[.]com and chatgpt[.]com using DPAPI and AES-256-GCM and injects the victim's ChatGPT/Claude/Gemini session tokens into the tool's own AI bridge.
- analyzed by
- Leitwacht
- first seen
- Aug 20, 2026, 06:46 PM
- analyzed
- Aug 20, 2026, 06:47 PM
Related advisories
- log-taker1@0.1.0
- eslint-helper-1@5.0.4
- eslint-helper@4.0.1
- parket-helper@0.0.1
- bqq1@1.0.0
- syjoy@1.0.0
- sysdo@1.0.0
- dakumangalsingh@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.