LWA-2026-7663 MAL-2026-13353 ↗ confirmed malware

stellarfixer@1.0.0

Malicious code in stellarfixer (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1547.001 · Registry Run Keys / Startup FolderT1053.005 · Scheduled TaskT1098 · Account ManipulationT1562.001 · Disable or Modify ToolsT1082 · System Information DiscoveryT1057 · Process DiscoveryT1012 · Query RegistryT1005 · Data from Local SystemT1056.001 · KeyloggingT1113 · Screen CaptureT1125 · Video CaptureT1071.001 · Web ProtocolsT1102 · Web ServiceT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 ChannelT1498 · Network Denial of Service

Analysis

stellarfixer@1.0.0 is a trojanized package that drops and executes the XWorm V7.0 remote access trojan (RAT) on Windows systems. The postinstall script (postinstall.js) runs the bundled PE binary bin/stellarfn.exe, which is a full-featured .NET RAT. Capabilities include: Telegram bot API C2 channel (api[.]telegram[.]org), keylogging via Windows hooks, screen capture, webcam capture via avicap32.dll, USB worm propagation to removable drives, persistence via scheduled tasks (schtasks.exe /create /sc minute /mo 1) and HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key, Windows Defender exclusion via Add-MpPreference, DDoS (SYN flood), hosts file hijacking (%drivers%\etc\hosts), system information theft (CPU, GPU, RAM, OS version, antivirus products), and remote plugin download/execution. The binary also sets the process as critical (RtlSetProcessIsCritical) to cause a BSOD if terminated.

analyzed by
Leitwacht
first seen
Aug 3, 2026, 05:27 PM
analyzed
Aug 3, 2026, 05:28 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.