moidevz@1.0.0
Malicious code in moidevz (npm)
Analysis
The package is a proctored-exam cheating tool. Its bin entry launches a detached Electron watchdog that clones the Electron binary as "SearchApp.exe" into %LOCALAPPDATA%\Microsoft\Windows\Diagnostics and respawns it if killed. It extracts and decrypts the victim's Chrome/Edge cookies for openai[.]com, chatgpt[.]com, claude[.]ai, and gemini[.]google[.]com (DPAPI + AES-256-GCM), injects those session tokens into hidden off-screen Electron windows, captures the foreground screen via GDI, sends exam questions to the AI services, and displays answers in a stealth overlay hidden from screen capture and proctoring software. It actively evades proctoring (Testpad/SEB) by manipulating window display affinity and z-order.
- analyzed by
- Leitwacht
- first seen
- Aug 26, 2026, 03:40 AM
- analyzed
- Aug 26, 2026, 03:41 AM
Related advisories
- shadxino@1.0.7
- passport811@1.0.0
- gekko-mev-bot@1.0.0
- system-performance-helper@1.0.1
- react-fontawesome-icons@1.0.5
- @salem_jalal/osc-components@1981.17.7
- parket-helper@0.0.1
- textdecode@1.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.