LWA-2026-7375 confirmed malware

@velliajs/telegram@1.0.0

Malicious code in @velliajs/telegram (npm)

T1195.002 · Compromise Software Supply ChainT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

@velliajs/telegram@1.0.0 is a trojanized clone of the telegraf Telegram bot framework. The package ships a hardcoded GitHub personal access token in src/telegraf.ts and lib/telegraf.js. When the TraceCors.create() method is called, it fetches a remote JSON database from api[.]github[.]com/repos/Vellia-Elyvia/mydb/contents/db.json using the hardcoded token, and checks whether the bot's username is registered and active. If the bot is not registered, the library throws an error and refuses to operate — a remote authorization gate / kill switch. This exfiltrates the bot's identity to the attacker's GitHub repository.

analyzed by
Leitwacht
first seen
Aug 1, 2026, 10:06 PM
analyzed
Aug 1, 2026, 10:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.