// the find
davidbombal/python-keylogger
A proof-of-concept Windows keylogger in Python that uses pynput to capture every keystroke and send the data to a remote server. The README presents it as educational, but its purpose is covert data capture. This evaluation is based on the README and file tree only; keylogger.py was not reviewed.
- The dependency footprint is small: one requirements file and no build system beyond the README steps.
- As a minimal example of how a keyboard hook and a network reporter fit together, it is readable enough to serve as a reference for how this class of software works, which is useful to people writing detection or defensive tooling.
- The README says the author compiled a custom PyInstaller bootloader to get the binary past antivirus on Windows 11. Evading endpoint detection is the defining feature of the malicious version of this tool, and that section should disqualify it from a developer picks email.
- Nothing in the README addresses consent, visible indicators, a stop mechanism, or limiting what gets captured. As described, it records all keystrokes, including passwords, and sends them off the machine.
- The last push was August 2022 and the project describes itself as a proof of concept, so there is no maintenance, no tests, and no security review of the transport or storage path. Not recommended for this email.