目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

syjoy

MAL-2026-14213
2026-08-19 02:50:45
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in syjoy (npm)

AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmsyjoy1.0.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-19T02:50:45Z","published":"2026-08-19T02:50:45Z","schema_version":"1.7.4","id":"MAL-2026-14213","summary":"Malicious code in syjoy (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d09a5d503a9a198f34720bcec601970125f514b666820b7a3b814e5d21bf1529)\nThe npm package syjoy advertises itself as a 'System binary configuration tool' but ships a Python payload (pointer.py) that harvests user data across processes and provides a remote input channel into the host. On first invocation, index.js silently installs Python 3.12 (via winget, falling back to a /quiet install of python-3.12.3-amd64.exe fetched from python.org) and launches pointer.py through start_tool.vbs, which uses ShellExecute cmd.exe with 'runas' and window-hidden flags to run elevated and invisibly; index.js spawns wscript.exe detached with stdio ignored and windowsHide true. pointer.py registers global keyboard hooks, reads the clipboard via pyperclip, captures screenshots via mss/ImageGrab, and walks other applications' UI Automation trees to extract text from arbitrary windows, then POSTs the harvested content to the hardcoded endpoint https://new-pointer.vercel.app/api. Responses from that endpoint are fed back to the host through pyautogui/keyboard automation (hotkeys such as '1+v', mash mode, 'a+v' force_paste), so the remote server chooses text that is typed into whichever window is focused. The Tk UI blanks window titles and uses transparent/overlay attributes to remain hidden. Internal mode names (aptitude, dsa, fullstack, aws, ocr) indicate the real function is a covert assessment/interview cheating overlay, not a binary configuration utility.\n","affected":[{"package":{"ecosystem":"npm","name":"syjoy"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"pointer.py","sha256":"040a190648080bc5f5141f9ee3a3ccabffddb571be9433033bd8ff3863541632","tlsh":"ade2fa05ec4d0896c473de2e5852b823ff1a0b435a1e9e57f8bc99901f743468ae4ef9"},{"path":"start_tool.vbs","sha256":"3016a3871b47653d754b00e72221d205bb90f667b9a4e58751cbf044d330fcf5","tlsh":"e3f0204f42bdc81be05741b253868c2ee2b3d350b021d55a9db8f889210c0f099733db"},{"path":"index.js","sha256":"8a2d3a7f4a8cc76665444ff335cdf03ffcc11ed8b81384d9ab95f3faab80d1a0","tlsh":"a9b1600a8a599234ac3147e99b072127e507a1636201e25cbdfe83880f76659c077fee"},{"path":"package.json","sha256":"adf3a2062224a545f9cd38959b7cee413eb462c3c2e12fa97c1421532e0f0ca4","tlsh":"6ee04f3789615ca345b48aa29a368a45b571cb3f00254c0f30fb901c9ba39b256aab5c"}],"package_integrity":[{"filename":"syjoy-1.0.0.tgz","hashes":{"sha1":"898955fa688b492c0909a950e3a3de79f9b473db","sha512_sri":"sha512-dWxeM9pK2FNAvB2zj0kSFU3dXYy9vUk+orJdyw/UvtaJHoeevv57IFPM1iBQzNDkiQ97hFKd2D4nciwfqyitoQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/syjoy/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018307","import_time":"2026-08-19T02:57:22.786762002Z","modified_time":"2026-08-19T02:50:45Z","sha256":"d09a5d503a9a198f34720bcec601970125f514b666820b7a3b814e5d21bf1529","source":"amazon-inspector","versions":["1.0.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0