LWA-2026-11632 confirmed malware

moidevz@1.0.0

Malicious code in moidevz (npm)

T1539 · Steal Web Session CookieT1555.003 · Credentials from Web BrowsersT1113 · Screen CaptureT1059.007 · JavaScriptT1562 · Impair DefensesT1027 · Obfuscated Files or Information

Analysis

The package is a proctored-exam cheating tool. Its bin entry launches a detached Electron watchdog that clones the Electron binary as "SearchApp.exe" into %LOCALAPPDATA%\Microsoft\Windows\Diagnostics and respawns it if killed. It extracts and decrypts the victim's Chrome/Edge cookies for openai[.]com, chatgpt[.]com, claude[.]ai, and gemini[.]google[.]com (DPAPI + AES-256-GCM), injects those session tokens into hidden off-screen Electron windows, captures the foreground screen via GDI, sends exam questions to the AI services, and displays answers in a stealth overlay hidden from screen capture and proctoring software. It actively evades proctoring (Testpad/SEB) by manipulating window display affinity and z-order.

analyzed by
Leitwacht
first seen
Aug 26, 2026, 03:40 AM
analyzed
Aug 26, 2026, 03:41 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.