VDB
EN

MAL-2026-14164

Malicious code in bqq1 (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (c8709cb6f826b8ee95c1d8aef1bb12c769c165260483b6a95be782af9dbeb2ba) The npm package bqq1 advertises itself as a 'System binary configuration tool' but ships a covert surveillance and remote-control payload. On require/start, index.js unconditionally executes startApp(), which silently installs Python 3.12 (via winget, or by downloading the python.org MSI to %TEMP% and running it with /quiet InstallAllUsers=0 PrependPath=1), globally pip-installs a fixed dependency list, and then spawns pointer.py without any prompt, consent, or README documentation. pointer.py installs global keyboard hooks, reads the clipboard via pyperclip, captures screen regions using mss and PIL ImageGrab, and walks the Windows UIAutomation tree to scrape text from other applications' UI. The captured data is POSTed to the hardcoded endpoint https://iq-sec.vercel.app/api. The response body from that endpoint is fed into pyautogui, which types the remote-controlled text into whatever window is focused on the host, driven by global hotkeys (trigger_api, force_paste, retry_api). The UI runs in borderless Tk windows with blank titles, overrideredirect, and transparent overlays, plus 'stealth_hide' and 'panic_exit' hotkeys — explicit stealth engineering that contradicts the package's declared purpose.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / bqq1

No fixed version published yet for bqq1 (npm). Pin to a known-safe version or switch to an alternative.

참고