VDB
KO

MAL-2026-14271

Malicious code in nodeberlin (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (0daee18c4afae327b271a2178e90822f750a17d97f7dfb1236e6dd37ef9410d9) The CLI polls the system clipboard every 300ms and captures full-desktop or user-snipped screen regions, then POSTs the JSON text and base64-encoded JPEG image data to a hardcoded author-controlled endpoint at https://tokyoap.vercel.app/api (API_URL). The destination is not caller-configurable and the package accepts no user-supplied API key, so all installers' clipboard contents and screenshots are routed through the author's proxy. On first run the bin auto-downloads the Python.org installer and pip-installs keyboard, pyautogui, pillow, pyperclip, and requests to support global hotkeys, screen capture, and the relay; a panic-exit hotkey and stealth overlay accompany the capture path. Clipboard buffers and screenshots routinely contain credentials, private messages, and other sensitive material; funnelling them through a hardcoded third-party endpoint materially harms the installer.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / nodeberlin

No fixed version published yet for nodeberlin (npm). Pin to a known-safe version or switch to an alternative.

References