Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

sysb1npm

sysb1 is a confirmed malicious npm package (MAL-2026-10428) that executes malicious code on install (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in sysb1 (npm)

MAL-2026-10428
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall sysb1

What this malware does

The npm package sysb1 advertises itself as a 'System binary configuration tool' but ships a Windows surveillance agent. index.js (declared as both main and bin) runs at load/start and silently installs the CPython 3.12 runtime via winget, falling back to downloading python-3.12.3-amd64.exe from python.org into the temp directory and running it with /quiet InstallAllUsers=0 PrependPath=1, then silently pip-installs surveillance libraries (keyboard, pyautogui, mss, uiautomation, pyperclip). It then spawns wscript.exe on start_tool.vbs detached and hidden; start_tool.vbs uses ShellExecute with the 'runas' verb and window state 0 to launch 'python pointer.py' as Administrator with no visible window. pointer.py captures clipboard content (pyperclip.paste), screenshots (ImageGrab, mss), and UI/accessibility text (uiautomation), and POSTs the collected data via requests.Session to a hardcoded endpoint https://iq-overlay-pointer.vercel.app/api that the installer did not configure. pointer.py also registers global keyboard hotkey hooks (keyboard.add_hotkey) that drive clipboard reads, screen OCR, keystroke injection (pyautogui.press), and network POSTs, running inside hidden overrideredirect/transparent-color Tk windows with a 'panic_exit' hotkey. Package metadata and identifiers ('IQPointer', 'ULTRA GHOST MODE', 'HACK 1/HACK 2', empty window titles) contradict the stated purpose and are a cover story.

Malicious versions

6 flagged
1.0.01.0.11.0.21.0.31.0.41.0.5

Indicators of compromise (SHA-256)

95e8cd8412bd88621ce6b01197ff69e0dc347d017175fcbfe378cdc036407e27
11f3fe2845ee2a07bcb82ebc43e8e28bdc4e35a96eee4bc2a82ac96c680807ea
c8f32dffecdfce99c809df1dcd7d18d75cdab188d294e4b67c901e4916e89966
530efe2fec0ffeabda93aa5e9718161f131bb28d35f28432d5d2c2da6e4763a4
6a81e81943d977a2c824a28ebbf6b78be0d78656f0dae96367f175d7fca5856b
9b98909d13a2ac5f3f00667317f85fc354009d43538a10bc0f9023bc443b17a6

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for sysb1 (6 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging sysb1 across your stack and pipelines.

  2. If you installed it — respond

    Remove sysb1 from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If sysb1 was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks sysb1 before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. sysb1 on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-009863IN-MAL-2026-010950IN-MAL-2026-010942IN-MAL-2026-017645IN-MAL-2026-018305IN-MAL-2026-018310

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks sysb1-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

sysb1 (npm) malicious package — MAL-2026-10428 | O3 Security