LWA-2026-11531 confirmed malware

moidevy@1.0.0

Malicious code in moidevy (npm)

T1552.003 · Credentials from Web BrowsersT1059.007 · JavaScriptT1059.001 · PowerShellT1059.003 · Windows Command ShellT1113 · Screen CaptureT1082 · System Information DiscoveryT1564.003 · Hidden WindowT1027 · Obfuscated Files or Information

Analysis

moidevy@1.0.0 is a Windows proctoring-evasion and exam-cheat tool disguised as a "DOM utility / diagnostic bridge". On launch it copies the bundled Electron binary to a stealth name "SearchApp.exe" and spawns a detached watchdog process that respawns itself every 2-15 seconds when killed, writing a log to %LOCALAPPDATA%\Microsoft\Windows\Diagnostics\boot.log. The Electron app sets the WDA_EXCLUDEFROMCAPTURE window flag and WS_EX_TOOLWINDOW/NOACTIVATE styles to hide its overlay from screen capture and Alt-Tab, actively demotes the proctoring application's window, and toggles its stealth flag off when it detects the proctor's core.exe process. It extracts on-screen exam text via Windows UI Automation (bin/uia_extract.py / uia_extract.exe) and PowerShell screen capture (bin/stealth_capture.ps1). It also ships bin/chrome_cookies.ps1, which decrypts Chrome, Edge, and Brave cookies for openai[.]com and chatgpt[.]com using DPAPI and AES-256-GCM and injects the victim's ChatGPT/Claude/Gemini session tokens into the tool's own AI bridge.

analyzed by
Leitwacht
first seen
Aug 20, 2026, 06:46 PM
analyzed
Aug 20, 2026, 06:47 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.