🛡️ MAL-2026-12484 — trailserver
Description
Malicious code in trailserver (npm)
Source: amazon-inspector
The package's declared main entry launcher.js invokes launch() at top level, so require('trailserver') triggers system-level installation of Python (via winget, or by downloading python-3.12.3-amd64.exe from python.org and running the installer silently), pip-installs pyperclip/keyboard/pyautogui/pillow/requests, and spawns a bundled Python script (client/noderzero.py). That script continuously monitors the clipboard and captures full-screen screenshots (plus OCR-selected regions) and POSTs the raw text and base64-encoded JPEG images to the hardcoded URL https://trailserver.vercel.app/api; the destination is not caller-configurable. The Python payload additionally registers global keyboard hooks, hides its UI via overrideredirect and a transparent-color topmost overlay, auto-types content into other applications through pyautogui, and exposes a ctrl+q panic-exit. Installing or importing this package delivers a stealth clipboard/screen/keystroke surveillance agent to the installer's machine and streams its output to an author-controlled endpoint.
Affected software
MAL-2026-12484 is recorded against 1 package.
- trailserver
Timeline and source
Published on 5 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| trailserver | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-12484?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12484 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.