@velliajs/telegram@1.0.0
Malicious code in @velliajs/telegram (npm)
Analysis
@velliajs/telegram@1.0.0 is a trojanized clone of the telegraf Telegram bot framework. The package ships a hardcoded GitHub personal access token in src/telegraf.ts and lib/telegraf.js. When the TraceCors.create() method is called, it fetches a remote JSON database from api[.]github[.]com/repos/Vellia-Elyvia/mydb/contents/db.json using the hardcoded token, and checks whether the bot's username is registered and active. If the bot is not registered, the library throws an error and refuses to operate — a remote authorization gate / kill switch. This exfiltrates the bot's identity to the attacker's GitHub repository.
- analyzed by
- Leitwacht
- first seen
- Aug 1, 2026, 10:06 PM
- analyzed
- Aug 1, 2026, 10:08 PM
Related advisories
- sui-migration-audit-rules@1.0.0
- streak-metrics-math@1.0.1
- streak-math-metrics@1.0.0
- streak-metrics-core@1.0.0
- add-two-numbers-x7q9m@1.0.0
- nagixjs@2.1.6
- @mypwn/greatcall.customers.commandapi@99.0.1
- @adominadmininstr/fmt-date-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.