VDB
Sign up

MAL-2026-16441

Malicious code in moidevl (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (76b05c7a5581562edc719cbaaf2f6b317d322a6a2ef96c9fc905b53394e42101) Despite a README describing a 'Windows diagnostic utility,' the package implements an anti-proctoring overlay for cheating on remote exams (Safe Exam Browser / AMCAT). main.js drives an Electron window hidden from screen capture via SetWindowDisplayAffinity(WDA_EXCLUDEFROMCAPTURE) and WS_EX_TOOLWINDOW/NOACTIVATE, launched as a detached process renamed to 'SearchApp.exe' to masquerade as Windows Search, and polls for a proctoring process 'core.exe' via `tasklist /FI "IMAGENAME eq core.exe"` to temporarily normalize the affinity flag while the proctor scans. bin/kalamasha-tool.js spawns a 'Ghost Watchdog' that copies node_modules/electron/dist/electron.exe to SearchApp.exe and immortally respawns it with backoff when killed, logging to %LOCALAPPDATA%\Microsoft\Windows\Diagnostics\boot.log. bin/chrome_cookies.ps1 walks Chrome/Edge/Brave 'User Data' profile directories, copies the locked Cookies SQLite DB to %TEMP%, reads the DPAPI-wrapped os_crypt.encrypted_key from Local State, and AES-256-GCM-decrypts cookie values for openai.com, chatgpt.com, auth0.openai.com and auth.openai.com; the decrypted cookies are injected into an embedded Electron session to drive those AI services under the browser owner's identity. main.js captures the foreground exam window (screenshot plus UI-Automation text extraction) and posts the content to https://ipc.shadxino.internal via HTTP POST from lines 364 and 368. The tarball also ships a 27MB opaque bin/uia_extract.exe alongside a Python source equivalent, invoked as `python "${pyPath}" || "${exePath}"`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/moidevl

No fixed version published yet for moidevl (npm). Pin to a known-safe version or switch to an alternative.

References