bamru@1.0.0
Malicious code in bamru (npm)
Analysis
bamru@1.0.0 is a covert clipboard and screen-capture exfiltration tool disguised as a "system binary configuration tool". On execution it auto-installs Python and a set of automation libraries, then launches a hidden background process (via a VBScript run with admin rights) that runs a transparent on-screen overlay. The overlay continuously monitors the system clipboard and, whenever the copied text changes, POSTs the clipboard contents to hxxps://new-pointer[.]vercel[.]app/api. It also captures full-screen screenshots (base64 JPEG) and extracts on-screen text via Windows UI Automation, sending those to the same endpoint. It then types the remote server's response back into the clipboard. The process runs detached and hidden, with stealth hotkeys (caps-lock to hide, 9+q to exit) and no visible window. Network IOC: hxxps://new-pointer[.]vercel[.]app/api (POST of clipboard text and screen images).
- analyzed by
- Leitwacht
- first seen
- Aug 25, 2026, 06:32 PM
- analyzed
- Aug 25, 2026, 06:33 PM
Related advisories
- sensivity@2.5.39
- bqq1@1.0.0
- syjoy@1.0.0
- sysdo@1.0.0
- gpt-terminal-cli@1.0.0
- wormgpt-cli@1.0.1
- ts-eslint-jest@1.0.0
- jest-formatter@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.