stellar-api-safe@1.0.8
Malicious code in stellar-api-safe (npm)
Analysis
A Discord bot wrapper that steals user tokens and refresh tokens. When installed and configured, the package creates a Discord bot that accepts /add commands to collect Discord tokens and refresh tokens from users, stores them in local JSON files, and exfiltrates them to hardcoded Discord webhooks (webhook IDs 1527809440084922462 and 1527807036350398687). On startup, the bot generates invite links for every guild it joins and posts them to the attacker's webhook. A background loop continuously sends stored refresh tokens to stellarapi-backend-production[.]up[.]railway[.]app and alerts the attacker via webhook on failures. The package depends on stellar-api-core, another package from the same publisher.
- analyzed by
- Leitwacht
- first seen
- Jul 23, 2026, 08:59 PM
- analyzed
- Jul 23, 2026, 09:00 PM
Related advisories
- @tobyvalk123/tixte@1.0.2
- vectormark@1.0.0
- xerohub-discord-voice-v2@1.8.0
- code-analyzer-mcp@1.0.0
- habingeer@2.1.6
- og-boost-br@1.0.0
- crypto-javas@2.0.8
- n8n-nodes-net-utils@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.