{"id":"MAL-2026-10134","summary":"Malicious code in stella-coder (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f0c3ed879ef15a68d537ad7b6ddb59508aba58eee49c8ca19b916ef59a0c2da6)\nstella-cli/telegram-bot.mjs hardcodes a Telegram bot API token (BOT_TOKEN = \"8923551485:AAFw4wG8ZwOtp5rzFsnguxhu4AH-2_ebSi0\") that is controlled by the package author. When the user invokes the /tg CLI command, the package starts a Telegram bot on the installer's machine that receives messages over api.telegram.org and passes them into execSync(`node stella-cli/index.mjs -p \"${text}\"`), invoking a shell-capable AI agent CLI with attacker-supplied input. Because the messaging channel is bound to a token the author retains, the author observes all bot traffic — including the 4-digit admin authorization code exchanged over that same channel — and can replay it to reach the command-execution path on any installer that enables /tg. telegram-bot.mjs additionally sends os.hostname() and os.userInfo().username to the same author-controlled bot. A hardcoded PREMIUM_CODE = \"10102013\" acts as a universal activation key that unlocks the remote-control feature-set without payment. package.json sets \"main\": \"stella-cli/index.mjs\", whose top-level executes main() and starts the interactive CLI on require/import, extending the reach of the /tg surface beyond the bin entry. There are no install lifecycle hooks; the backdoor fires when the user runs the CLI (or a consumer imports the module) and invokes /tg.\n","modified":"2026-07-14T07:19:16.035090390Z","published":"2026-07-10T15:59:07Z","database_specific":{"malicious-packages-origins":[{"sha256":"14c39e61e71e2a0e8cdbd42c8dc974ff425e03b27bc8a062b7c64cd6e09a0382","import_time":"2026-07-10T16:19:43.048541644Z","id":"IN-MAL-2026-009629","modified_time":"2026-07-10T15:59:17Z","versions":["5.0.0"],"source":"amazon-inspector"},{"source":"amazon-inspector","sha256":"9dbd590476f6ed75799dfbea98c4f3e1d30f09d02fce6081afed3f95411ea07b","import_time":"2026-07-10T16:19:42.915036906Z","id":"IN-MAL-2026-009628","modified_time":"2026-07-10T15:59:07Z","versions":["5.1.0"]},{"versions":["5.1.1"],"source":"amazon-inspector","sha256":"e7c1d21730856f349a9a7ae0af9ac0a96b018eaecb8e09356769087238da7449","import_time":"2026-07-10T16:19:43.294718076Z","id":"IN-MAL-2026-009631","modified_time":"2026-07-10T15:59:33Z"},{"id":"IN-MAL-2026-009630","modified_time":"2026-07-10T15:59:24Z","versions":["4.0.0"],"source":"amazon-inspector","sha256":"f0c3ed879ef15a68d537ad7b6ddb59508aba58eee49c8ca19b916ef59a0c2da6","import_time":"2026-07-10T16:19:43.171866894Z"},{"source":"amazon-inspector","sha256":"735f977af77fc57d1a4bf8e68e001c9c72445b0440fb4de0703a64c6702ed7eb","import_time":"2026-07-10T16:19:43.392758621Z","id":"IN-MAL-2026-009632","modified_time":"2026-07-10T15:59:42Z","versions":["5.0.1"]},{"sha256":"79b07b496c037e1933c66f3f9f84a8cfcc92e9b647b78735f6f30e9d3763cee4","import_time":"2026-07-10T16:19:43.678138713Z","id":"IN-MAL-2026-009634","modified_time":"2026-07-10T15:59:59Z","versions":["5.1.2"],"source":"amazon-inspector"},{"import_time":"2026-07-12T22:20:08.531491563Z","id":"IN-MAL-2026-009785","modified_time":"2026-07-12T22:09:38Z","versions":["5.2.0"],"source":"amazon-inspector","sha256":"d7e7711640d340391b9d6e0c8276ae3d65cb4062a91b8c941cb3133524ac94cb"},{"import_time":"2026-07-13T22:21:57.731398954Z","id":"IN-MAL-2026-010351","modified_time":"2026-07-13T22:16:53Z","versions":["5.3.3"],"source":"amazon-inspector","sha256":"06343d2c610ca6b60c107a7fbf12286d4b83cd74cdc9520fa0a7abd7f8d02ba8"},{"source":"amazon-inspector","sha256":"55868932073c1410619567f6340b07714d6b259e103e3a0c5e6119f7a7af0453","import_time":"2026-07-13T22:21:57.661417532Z","id":"IN-MAL-2026-010350","modified_time":"2026-07-13T22:16:46Z","versions":["5.3.4"]},{"id":"IN-MAL-2026-010349","modified_time":"2026-07-13T22:16:35Z","versions":["5.3.5"],"source":"amazon-inspector","sha256":"7305a7fd1053b2b87da26ee88d78573d94a4615a2b7582949db17fb9d8c8cb60","import_time":"2026-07-13T22:21:57.601195437Z"},{"import_time":"2026-07-14T06:49:56.906202365Z","id":"IN-MAL-2026-010480","modified_time":"2026-07-14T05:57:56Z","versions":["5.3.6"],"source":"amazon-inspector","sha256":"c3522574dfb1b4a4538d51008e2b26d6baa4ea5a2f718aaccb6db3eb1564faf4"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/5.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/5.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/5.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/4.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/5.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/5.1.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/5.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/5.3.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/5.3.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/5.3.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stella-coder/v/5.3.6"}],"affected":[{"package":{"name":"stella-coder","ecosystem":"npm","purl":"pkg:npm/stella-coder"},"versions":["5.0.0","5.1.0","5.1.1","4.0.0","5.0.1","5.1.2","5.2.0","5.3.3","5.3.4","5.3.5","5.3.6"],"database_specific":{"indicators":{"package_integrity":[{"filename":"stella-coder-5.0.0.tgz","hashes":{"sha1":"27497851e98fa52451ec4b3160487d1715cf9169","sha512_sri":"sha512-uO8NgQrlBI+mRyRPRWWyBsGSfEtrHcN8z5RmIkX6jFOuWJHsxLaGtnXiYBNIwf96/ZbHbhFUsv8HSlc/eRT/1w=="}}],"evidence_files":[{"sha256":"79d66206b49c7780e4441c039ae69d9bd83ed9cbd9bb486d6b34105e0e498d5b","tlsh":"eed2f7a130ba56244242bda6d53a3d053635c26ffe293d90787d47e42f3d86cceb9788","path":"stella-cli/telegram-bot.mjs"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/stella-coder/MAL-2026-10134.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}