nodetokyo@1.0.9
Malicious code in nodetokyo (npm)
Analysis
nodetokyo is a Windows "stealth assistant" that installs a hidden background process which continuously harvests the user's clipboard and screen contents and transmits them to a remote endpoint. The bin entry (launcher.js) auto-installs Python — via winget, or by downloading hxxps://www[.]python[.]org/ftp/python/3[.]12[.]3/python-3[.]12[.]3-amd64[.]exe and executing it silently — pip-installs pyperclip/keyboard/pyautogui/Pillow, then spawns client/noderzero.py as a detached, unref'd process that outlives the terminal. The Python payload registers global keyboard hooks, including a suppress-mode on_press handler that intercepts all keystrokes, polls the clipboard every 300 ms, and POSTs every clipboard change of 5+ characters as JSON to hxxps://nodetokyo[.]vercel[.]app/api; it also captures full-screen screenshots (PIL ImageGrab) and POSTs them base64-encoded JPEG to the same endpoint. The UI is deliberately invisible — an overrideredirect, transparent, always-on-top window that hides on Esc and exits via os._exit(0) — and it can auto-type server-supplied text into any focused window via pyautogui. Because the clipboard monitor is indiscriminate, passwords, tokens and private keys copied by the user are sent to the remote service alongside ordinary text. IOCs: hxxps://nodetokyo[.]vercel[.]app/api (collection/C2 endpoint); hxxps://www[.]python[.]org/ftp/python/3[.]12[.]3/python-3[.]12[.]3-amd64[.]exe (downloaded and silently executed).
- analyzed by
- Leitwacht
- first seen
- Oct 6, 2026, 03:20 PM
- analyzed
- Oct 8, 2026, 12:08 PM
Related advisories
- random-certs@0.0.1
- wallet-connect-adapter@1.4.2
- sysdo@1.0.0
- core-js-buffer@1.0.0
- @ethers-js/contracts@6.9.0
- n8n-nodes-devops-utils@1.0.0
- txs-runner-lib@1.0.1
- txs-random-lib@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.