LWA-2026-11616 confirmed malware

bamru@1.0.0

Malicious code in bamru (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1115 · Clipboard DataT1113 · Screen CaptureT1041 · Exfiltration Over C2 ChannelT1567 · Exfiltration Over Web ServiceT1564 · Hide Artifacts

Analysis

bamru@1.0.0 is a covert clipboard and screen-capture exfiltration tool disguised as a "system binary configuration tool". On execution it auto-installs Python and a set of automation libraries, then launches a hidden background process (via a VBScript run with admin rights) that runs a transparent on-screen overlay. The overlay continuously monitors the system clipboard and, whenever the copied text changes, POSTs the clipboard contents to hxxps://new-pointer[.]vercel[.]app/api. It also captures full-screen screenshots (base64 JPEG) and extracts on-screen text via Windows UI Automation, sending those to the same endpoint. It then types the remote server's response back into the clipboard. The process runs detached and hidden, with stealth hotkeys (caps-lock to hide, 9+q to exit) and no visible window. Network IOC: hxxps://new-pointer[.]vercel[.]app/api (POST of clipboard text and screen images).

analyzed by
Leitwacht
first seen
Aug 25, 2026, 06:32 PM
analyzed
Aug 25, 2026, 06:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.