Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

nodetokyonpm

nodetokyo is a confirmed malicious npm package (MAL-2026-16388) that steals credentials and exfiltrates sensitive data (malicious version 1.0.8). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in nodetokyo (npm)

MAL-2026-16388
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall nodetokyo

What this malware does

The package's declared main (launcher.js) executes launch() at module top level, so require('nodetokyo') automatically installs Python 3.12 (via winget or by downloading the python.org installer and running it silently), pip-installs pyperclip/keyboard/requests/pillow/pyautogui, and spawns a detached, window-hidden background process running the bundled Python payload. That payload polls the OS clipboard every 300ms and, in auto-scan mode, captures full-screen screenshots every 30s, POSTing {'text':...} and {'image': <base64>} to the hardcoded endpoint https://nodetokyo.vercel.app/api (see API_URL in the bundled script; clipboard_monitor()/scan_screen call session.post(API_URL,...)). The destination is not caller-configurable. The payload also registers global system-wide keyboard hooks via the Python keyboard module (keyboard.on_press with suppress=True; keyboard.add_hotkey('ctrl+c',...)) and renders an always-on-top Tk window with overrideredirect(True) and -transparentcolor white to remain visually hidden, with a Ctrl+Q panic_exit. Package keywords include 'stealth' and the description advertises a 'Stealth Assistant'. Whatever the installer copies to the clipboard — including passwords, tokens, and private messages — and whatever appears on screen is transmitted to the author's endpoint without a per-item prompt.

Malicious versions

1 flagged
1.0.8

Indicators of compromise (SHA-256)

9ec0e3f7b963353d4d2928e12ca3898cce5100ed3e3537383faa9c7f9a93f203

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for nodetokyo (version 1.0.8). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging nodetokyo across your stack and pipelines.

  2. If you installed it — respond

    nodetokyo is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If nodetokyo was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks nodetokyo before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. nodetokyo on npm has been identified as a malicious package (version 1.0.8 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-020295

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks nodetokyo-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

nodetokyo (npm) malicious package — MAL-2026-16388 | O3 Security