LWA-2026-7075 confirmed malware

stellar-api-safe@1.0.8

Malicious code in stellar-api-safe (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

A Discord bot wrapper that steals user tokens and refresh tokens. When installed and configured, the package creates a Discord bot that accepts /add commands to collect Discord tokens and refresh tokens from users, stores them in local JSON files, and exfiltrates them to hardcoded Discord webhooks (webhook IDs 1527809440084922462 and 1527807036350398687). On startup, the bot generates invite links for every guild it joins and posts them to the attacker's webhook. A background loop continuously sends stored refresh tokens to stellarapi-backend-production[.]up[.]railway[.]app and alerts the attacker via webhook on failures. The package depends on stellar-api-core, another package from the same publisher.

analyzed by
Leitwacht
first seen
Jul 23, 2026, 08:59 PM
analyzed
Jul 23, 2026, 09:00 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.