Malicious code in stellar-api-core (npm)
The npm package stellar-api-core contained malicious code that injected a hardcoded Discord admin account into every deployment, enabling credential theft and unauthorized guild access. The malicious code exfiltrated user tokens and guild invites to attacker-controlled Discord webhooks.
- Disclosed
- Last updated
- Blast radius
- All deployments of stellar-api-core bot using affected versions
- Ecosystems
- Attack vectors
- Affected entities
- stellar-api-corenpm package containing malicious code
The npm package stellar-api-core was found to contain malicious code that compromised the security of every deployment. The package's constructor unconditionally appended a hardcoded Discord user ID (1489655840662093854) to the caller-supplied adminIds list, granting persistent admin access to an attacker-controlled account.\n\nThe injected admin could retrieve sensitive credentials through the bot's admin panel. Specifically, the stellar_panel_dropdown handler's handleManualRefresh function returned users' Nakama access and refresh tokens as a Discord attachment (token.json), allowing the attacker to extract installer and user credentials from running deployments.\n\nAdditionally, the malicious code exfiltrated data to two hardcoded Discord webhook URLs without user disclosure or opt-out. These webhooks received permanent invite links for every guild the bot joined, plus notifications whenever user tokens were added, refreshed, or deleted. This enabled the attacker to join target guilds and extract user tokens via the admin panel.\n\nThe incident was identified and credited to the OpenSSF's malicious-packages project.
Indicators of compromise
- Packages
- stellar-api-core
- Domains
- discord.com/api/webhooks/1527809440084922462
- discord.com/api/webhooks/1527807036350398687
Remediation
- Immediately remove stellar-api-core from all deployments
- Audit all Discord guilds where the bot was deployed for unauthorized access
- Rotate all Nakama access and refresh tokens that may have been exposed
- Review Discord webhook logs for exfiltrated invite links and token notifications
- Revoke the hardcoded Discord admin account (ID: 1489655840662093854) from all guilds
- Use a trusted, verified alternative package or fork the package from a clean source
- Implement package integrity verification and dependency scanning in CI/CD pipelines
Sources
- GitHub Advisory GHSA-6c8r-cv56-5h9h · GitHub Advisory Database
Cite this entry
"Malicious code in stellar-api-core (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 5, 2026; last updated August 5, 2026. https://supplychainattack.org/incident/malicious-code-in-stellar-api-core-npm-1x4dwm
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malware in @siwatfa/yorn
Malware was discovered in the npm package @siwatfa/yorn. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @ai-vertical/ai-agent
Malware was discovered in the npm package @ai-vertical/ai-agent. Systems with this package installed or running should be considered fully compromised and require immediate remediation.
npmAI agents & skillsCompromised package - resolvedcritical
Malicious code in epic-sso (npm)
The npm package epic-sso was found to contain malicious code. The package was identified by Amazon Inspector and reported through the OpenSSF malicious packages database.
npmCompromised package - containedcritical
Malicious code in pfp-forms-sme-loan (npm)
The npm package pfp-forms-sme-loan contains malicious code that executes a hidden loader on import, downloading and running platform-specific native payloads from attacker-controlled Cloudflare Workers hosts or reconstructing them via DNS TXT records under well1.site. Any system that imported this package should be considered compromised.
npmCompromised packageMalicious commit