stellarfixer@1.0.0
Malicious code in stellarfixer (npm)
Analysis
stellarfixer@1.0.0 is a trojanized package that drops and executes the XWorm V7.0 remote access trojan (RAT) on Windows systems. The postinstall script (postinstall.js) runs the bundled PE binary bin/stellarfn.exe, which is a full-featured .NET RAT. Capabilities include: Telegram bot API C2 channel (api[.]telegram[.]org), keylogging via Windows hooks, screen capture, webcam capture via avicap32.dll, USB worm propagation to removable drives, persistence via scheduled tasks (schtasks.exe /create /sc minute /mo 1) and HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key, Windows Defender exclusion via Add-MpPreference, DDoS (SYN flood), hosts file hijacking (%drivers%\etc\hosts), system information theft (CPU, GPU, RAM, OS version, antivirus products), and remote plugin download/execution. The binary also sets the process as critical (RtlSetProcessIsCritical) to cause a BSOD if terminated.
- analyzed by
- Leitwacht
- first seen
- Aug 3, 2026, 05:27 PM
- analyzed
- Aug 3, 2026, 05:28 PM
Related advisories
- osinthell@1.9.5
- basic-vite@1.0.0
- env-config-f281@1.0.0
- system-performance-helper@1.0.1
- wormgpt-cli@1.0.1
- web3-token-helper@1.1.3
- xeiko-cdn@1.0.0
- gpt-terminal-cli@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.