MAL-2026-10428Malicious code in sysb1 (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
1.0.0 | unavailable | — | — | — |
1.0.1 | unavailable | — | — | — |
1.0.2 | unavailable | — | — | — |
1.0.4 | unavailable | — | — | — |
| Ecosystem | Package | Version |
|---|---|---|
| npm | sysb1 | 1.0.0 |
| npm | sysb1 | 1.0.1 |
| npm | sysb1 | 1.0.2 |
| npm | sysb1 | 1.0.3 |
| npm | sysb1 | 1.0.4 |
| npm | sysb1 | 1.0.5 |
{"schema_version":"1.7.4","id":"MAL-2026-10428","published":"2026-07-13T08:10:57Z","modified":"2026-08-19T02:59:18.396334203Z","summary":"Malicious code in sysb1 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (530efe2fec0ffeabda93aa5e9718161f131bb28d35f28432d5d2c2da6e4763a4)\nThe npm package sysb1 advertises itself as a 'System binary configuration tool' but ships a Windows surveillance agent. index.js (declared as both main and bin) runs at load/start and silently installs the CPython 3.12 runtime via winget, falling back to downloading python-3.12.3-amd64.exe from python.org into the temp directory and running it with /quiet InstallAllUsers=0 PrependPath=1, then silently pip-installs surveillance libraries (keyboard, pyautogui, mss, uiautomation, pyperclip). It then spawns wscript.exe on start_tool.vbs detached and hidden; start_tool.vbs uses ShellExecute with the 'runas' verb and window state 0 to launch 'python pointer.py' as Administrator with no visible window. pointer.py captures clipboard content (pyperclip.paste), screenshots (ImageGrab, mss), and UI/accessibility text (uiautomation), and POSTs the collected data via requests.Session to a hardcoded endpoint https://iq-overlay-pointer.vercel.app/api that the installer did not configure. pointer.py also registers global keyboard hotkey hooks (keyboard.add_hotkey) that drive clipboard reads, screen OCR, keystroke injection (pyautogui.press), and network POSTs, running inside hidden overrideredirect/transparent-color Tk windows with a 'panic_exit' hotkey. Package metadata and identifiers ('IQPointer', 'ULTRA GHOST MODE', 'HACK 1/HACK 2', empty window titles) contradict the stated purpose and are a cover story.\n","affected":[{"package":{"name":"sysb1","ecosystem":"npm"},"versions":["1.0.0","1.0.2","1.0.1","1.0.4","1.0.5","1.0.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"pointer.py","sha256":"a095aa6a4b08da23c6f2267bc18fe5f47342a3fa3225309796f54e1935f43207","tlsh":"4af22e09ec1d089ac073cd2f5952a853ff1a07439a5eda17f8bc99901f743468ae4ef9"},{"path":"index.js","sha256":"6044ff1e5d1929c7e31b6e77a4c000ae9400229fbd5733821f88fd2bad8f4cea","tlsh":"de8150075a95a234ed7247a99b07212be517a073b100e69cbcbe83840f76945c073fee"},{"path":"package.json","sha256":"139c49539ac589af5ba968636afa7ab26d48e8329bd119f40f96e3c8dc025731","tlsh":"7ce04f3399615c9344b58aa29a368a05b5718b3f00254c0f31bb511c97a29a245bbb5c"}],"package_integrity":[{"filename":"sysb1-1.0.0.tgz","hashes":{"sha1":"b4f01fdae03300e650abc68fb08988f6dc79d6ed","sha512_sri":"sha512-1CCAnieozV/7MSJ8BwTTmNK2hPScUQa9rDzqdamzfdgJSQFvaOoxeI/9Y1I/Wqm+kDzKhE6i/ZYus4d2Jf4tew=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.3"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-009863","import_time":"2026-07-13T09:10:56.016202745Z","modified_time":"2026-07-13T08:10:57Z","sha256":"95e8cd8412bd88621ce6b01197ff69e0dc347d017175fcbfe378cdc036407e27","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-010950","import_time":"2026-07-28T14:20:00.972282697Z","modified_time":"2026-07-28T13:40:44Z","sha256":"11f3fe2845ee2a07bcb82ebc43e8e28bdc4e35a96eee4bc2a82ac96c680807ea","source":"amazon-inspector","versions":["1.0.2"]},{"id":"IN-MAL-2026-010942","import_time":"2026-07-28T14:20:00.299051627Z","modified_time":"2026-07-28T13:39:41Z","sha256":"c8f32dffecdfce99c809df1dcd7d18d75cdab188d294e4b67c901e4916e89966","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-017645","import_time":"2026-08-13T17:24:45.807833456Z","modified_time":"2026-08-13T17:17:15Z","sha256":"530efe2fec0ffeabda93aa5e9718161f131bb28d35f28432d5d2c2da6e4763a4","source":"amazon-inspector","versions":["1.0.4"]},{"id":"IN-MAL-2026-018305","import_time":"2026-08-19T02:57:22.605974205Z","modified_time":"2026-08-19T02:50:27Z","sha256":"6a81e81943d977a2c824a28ebbf6b78be0d78656f0dae96367f175d7fca5856b","source":"amazon-inspector","versions":["1.0.5"]},{"id":"IN-MAL-2026-018310","import_time":"2026-08-19T02:57:23.07809155Z","modified_time":"2026-08-19T02:51:09Z","sha256":"9b98909d13a2ac5f3f00667317f85fc354009d43538a10bc0f9023bc443b17a6","source":"amazon-inspector","versions":["1.0.3"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0