Loading npm security reports…
NodeTokyo - AI-Powered Stealth Assistant. Run anywhere with node.
OpenSSF/OSV advisory MAL-2026-14270 confirms this npm version as malicious. The package installs a global keyboard hook (keyboard.add_hotkey on ctrl+c), polls the system clipboard every 300ms via pyperclip.paste(), and captures full-screen screenshots via ImageGrab.grab(). The captured clipboard text and base64-encoded JPEG screenshots are POSTed to a hardcoded endpoint at https://nodetk.vercel.app/api (API_URL constant, session.post(API_URL, json={'image': img_data,...}))...
Package ships non-JavaScript build or shell helper files.
client/noderzero.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
client/noderzero.pyView on unpkg