MAL-2026-14271

    Dashboard / Malicious Package / MAL-2026-14271

    MAL-2026-14271

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in nodeberlin (npm)

    Details: Source: amazon-inspector (0daee18c4afae327b271a2178e90822f750a17d97f7dfb1236e6dd37ef9410d9) The CLI polls the system clipboard every 300ms and captures full-desktop or user-snipped screen regions, then POSTs the JSON text and base64-encoded JPEG image data to a hardcoded author-controlled endpoint at https://tokyoap.vercel.app/api (API_URL). The destination is not caller-configurable and the package accepts no user-supplied API key, so all installers' clipboard contents and screenshots are routed through the author's proxy. On first run the bin auto-downloads the Python.org installer and pip-installs keyboard, pyautogui, pillow, pyperclip, and requests to support global hotkeys, screen capture, and the relay; a panic-exit hotkey and stealth overlay accompany the capture path. Clipboard buffers and screenshots routinely contain credentials, private messages, and other sensitive material; funnelling them through a hardcoded third-party endpoint materially harms the installer.

    Affected packages

    Package

    Name: nodeberlin

    Purl: pkg:npm/nodeberlin

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.7
    MAL-2026-14271 | CVE-DB