{"id":"MAL-2026-16441","summary":"Malicious code in moidevl (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (76b05c7a5581562edc719cbaaf2f6b317d322a6a2ef96c9fc905b53394e42101)\nDespite a README describing a 'Windows diagnostic utility,' the package implements an anti-proctoring overlay for cheating on remote exams (Safe Exam Browser / AMCAT). main.js drives an Electron window hidden from screen capture via SetWindowDisplayAffinity(WDA_EXCLUDEFROMCAPTURE) and WS_EX_TOOLWINDOW/NOACTIVATE, launched as a detached process renamed to 'SearchApp.exe' to masquerade as Windows Search, and polls for a proctoring process 'core.exe' via `tasklist /FI \"IMAGENAME eq core.exe\"` to temporarily normalize the affinity flag while the proctor scans. bin/kalamasha-tool.js spawns a 'Ghost Watchdog' that copies node_modules/electron/dist/electron.exe to SearchApp.exe and immortally respawns it with backoff when killed, logging to %LOCALAPPDATA%\\Microsoft\\Windows\\Diagnostics\\boot.log. bin/chrome_cookies.ps1 walks Chrome/Edge/Brave 'User Data' profile directories, copies the locked Cookies SQLite DB to %TEMP%, reads the DPAPI-wrapped os_crypt.encrypted_key from Local State, and AES-256-GCM-decrypts cookie values for openai.com, chatgpt.com, auth0.openai.com and auth.openai.com; the decrypted cookies are injected into an embedded Electron session to drive those AI services under the browser owner's identity. main.js captures the foreground exam window (screenshot plus UI-Automation text extraction) and posts the content to https://ipc.shadxino.internal via HTTP POST from lines 364 and 368. The tarball also ships a 27MB opaque bin/uia_extract.exe alongside a Python source equivalent, invoked as `python \"${pyPath}\" || \"${exePath}\"`.\n","modified":"2026-09-23T03:00:06.222609257Z","published":"2026-09-23T02:44:31Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-23T02:46:21.8083142Z","modified_time":"2026-09-23T02:44:31Z","sha256":"76b05c7a5581562edc719cbaaf2f6b317d322a6a2ef96c9fc905b53394e42101","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020342"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/moidevl/v/1.0.0"}],"affected":[{"package":{"name":"moidevl","ecosystem":"npm","purl":"pkg:npm/moidevl"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"0983d75a606511318433af758b3b6d16f726a523e0419354beacc3d82fb1419ceb2fee","path":"main.js","sha256":"23b15a5a2d9fcea02a14d66e8c04f7d46cb38a04b3e6bfd55705f14ade8944b5"},{"tlsh":"1c3264a67812514c10f15f39e9f698a8f91e9027d1e60918fddcc4e01f7046adef8f69","path":"bin/chrome_cookies.ps1","sha256":"21b61ec810331850d72423c40c5448e6cd310c4cfad6aed54f92cd7e7cac5f3a"},{"path":"bin/kalamasha-tool.js","sha256":"0c293be90c10c8a7618d25f4c4811fa63612b7bc5199b86e10bb31eb36c716dd","tlsh":"eee121499267233499b15fea57321c1adb2b9123d5446344b89c83ca3f3642ccdb6fee"}],"package_integrity":[{"filename":"moidevl-1.0.0.tgz","hashes":{"sha1":"2b6e945f59d46aee9d05ff151321c650eec34562","sha512_sri":"sha512-Yxd+ZqWt8G8ENCeE827PVgRnNqzo7vtR/W2xycLRu6XMXo/Y3k4WZiluBpqstsHfGu6Jp4Dm64KQg343PUKoyw=="}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/moidevl/MAL-2026-16441.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}