AI called this Malicious at 98.0% confidence as Malware with low false-positive risk.
Evidence for block
- The executable launches pointer.py after the user runs the gfff5 CLI.
- pointer.py polls the clipboard and automatically posts changed text to a hard-coded remote API.
- It captures a full screen, base64-encodes it, and posts the image to that API.
- The UI is deliberately near-invisible and provides stealth hide/show hotkeys.
Evidence against
- package.json has no preinstall, install, or postinstall lifecycle hook.
- Screen capture is initiated through a registered hotkey, although clipboard transfer is automatic.
Behavioral surface
SourceChildProcessEnvironmentVarsFilesystemShell
Supply chainHighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 1 file(s), 4.09 KB of source, external domains: www.python.org