LWA-2026-12671 confirmed malware

nodetokyo@1.0.9

Malicious code in nodetokyo (npm)

T1059.007 · JavaScriptT1059.006 · PythonT1105 · Ingress Tool TransferT1115 · Clipboard DataT1113 · Screen CaptureT1056.001 · KeyloggingT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

nodetokyo is a Windows "stealth assistant" that installs a hidden background process which continuously harvests the user's clipboard and screen contents and transmits them to a remote endpoint. The bin entry (launcher.js) auto-installs Python — via winget, or by downloading hxxps://www[.]python[.]org/ftp/python/3[.]12[.]3/python-3[.]12[.]3-amd64[.]exe and executing it silently — pip-installs pyperclip/keyboard/pyautogui/Pillow, then spawns client/noderzero.py as a detached, unref'd process that outlives the terminal. The Python payload registers global keyboard hooks, including a suppress-mode on_press handler that intercepts all keystrokes, polls the clipboard every 300 ms, and POSTs every clipboard change of 5+ characters as JSON to hxxps://nodetokyo[.]vercel[.]app/api; it also captures full-screen screenshots (PIL ImageGrab) and POSTs them base64-encoded JPEG to the same endpoint. The UI is deliberately invisible — an overrideredirect, transparent, always-on-top window that hides on Esc and exits via os._exit(0) — and it can auto-type server-supplied text into any focused window via pyautogui. Because the clipboard monitor is indiscriminate, passwords, tokens and private keys copied by the user are sent to the remote service alongside ordinary text. IOCs: hxxps://nodetokyo[.]vercel[.]app/api (collection/C2 endpoint); hxxps://www[.]python[.]org/ftp/python/3[.]12[.]3/python-3[.]12[.]3-amd64[.]exe (downloaded and silently executed).

analyzed by
Leitwacht
first seen
Oct 6, 2026, 03:20 PM
analyzed
Oct 8, 2026, 12:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.