VDB
GCVE-110-OSM-2026-8614
GCVE-110-OSM-2026-8614
Advisory PublishedCVSS 5.4/10
This package markets itself as an AI coding agent but contains several convergent trust concerns. Most critically, a hardcoded Telegram bot token (`8923551485:AAFw4wG8ZwOtp5rzFsnguxhu4AH-2_ebSi0`) is embedded across multiple files, meaning all users share a single bot controlled by the package author — the author can monitor all user interactions. All AI inference is routed through the author-controlled `https://opencode.ai/zen/v1` endpoint, creating a central chokepoint for harvesting user prompts and API keys. The `getHardwareInfo` function in `security.mjs` collects hardware-bound identifiers, files are hidden from the OS with `attrib +h +s`, screen monitoring via PowerShell and browser control are baked in, and .env files from the user's working directory are silently parsed and loaded into the process environment. The account is 11 days old with 18 versions in 5 days, a single-package publisher, and no prior history. While each individual capability is claimed as a feature in the description, the combination — single bot token for all users, author-controlled API proxy, hardware fingerprinting, screen/browser access, and env-file slurping — constitutes a surveillance architecture that warrants manual review before use.
ENTRY
stella-cli/index.mjs (bin: stella-cli/index.mjs)
- Hidden NPM Install in releases/stella-coder/build.mjs: "exec(`npx postject ${targetExe} NODE_SEA_BLOB ${SEA_BLOB} --sentinel-fuse NODE_S..."
- Hidden NPM Install in stella-cli/build.mjs: "exec(`npx postject ${targetExe} NODE_SEA_BLOB ${SEA_BLOB} --sentinel-fuse NODE_S..."
PERSISTENCE
- Cron Job Persistence in dist/tools.mjs: "crontab -"
- Cron Job Persistence in releases/stella-coder/tools.mjs: "crontab -"
- Cron Job Persistence in stella-cli/tools.mjs: "crontab -"
DESTINATION
- reconstructed: http://localhost:11434/api/chat (primary, reconstructed) in dist/index.mjs
- reconstructed: https://api.telegram.org/bot8923551485:AAFw4wG8ZwOtp5rzFsnguxhu4AH-2_ebSi0 (reconstructed) in dist/index.mjs
- custom-c2: localhost:11434 (reconstructed) in dist/index.mjs
- custom-c2: api.telegram.org (reconstructed) in releases/stella-coder/telegram-bot.mjs
- telegram-bot: 8923551485:AAFw4wG8ZwOtp5rzFsnguxhu4AH-2_ebSi0 (plaintext) in releases/stella-coder/telegram-bot.mjs
- telegram-bot: api.telegram.org/bot${BOT_TOKEN}` (plaintext) in releases/stella-coder/telegram-bot.mjs
- custom-c2: www.pexels.com (plaintext) in .opencode/skills/design-system/scripts/fetch-background.py
- custom-c2: laravel.com (plaintext) in .opencode/skills/ui-ux-pro-max/data/stacks/laravel.csv
(+7 more)
EXFIL
- Corporate Environment Targeting in .opencode/skills/ui-ux-pro-max/data/styles.csv: "tmosphere.","background: linear-gradient(180deg, #FF71CE, #01CDFE, #B967FF), fil..."
- Corporate Environment Targeting in dist/index.mjs: "tMode = args.includes("-p") || args.includes"
- Corporate Environment Targeting in releases/stella-coder/index.mjs: "tMode = args.includes("-p") || args.includes"
- Corporate Environment Targeting in stella-cli/index.mjs: "tMode = args.includes("-p") || args.includes"
- Data Encoding for Exfiltration in .opencode/skills/design/scripts/cip/render-html.py: "base64.b64encode("
- Data Encoding for Exfiltration in .opencode/skills/design-system/scripts/fetch-background.py: "urllib.parse.quote("
- Data Encoding for Exfiltration in dist/index.mjs: "encodeURIComponent(arg)}` : "https://www.kinopoisk.ru"
- Data Encoding for Exfiltration in dist/tools.mjs: "encodeURIComponent(query)}&format=json&no_html=1&skip_disambig=1"
(+53 more)
OBFUSCATION
- Dynamic Base64 Decoding in dist/security.mjs: "Buffer.from(encryptedBase64, "base64")"
- Dynamic Base64 Decoding in releases/stella-coder/security.mjs: "Buffer.from(encryptedBase64, "base64")"
- Dynamic Base64 Decoding in stella-cli/security.mjs: "Buffer.from(encryptedBase64, "base64")"
- String Array Obfuscation in .opencode/skills/ui-ux-pro-max/scripts/core.py: "["saas", "ecommerce", "e-commerce", "fintech", "healthcare", "gaming", "portfoli..."
- Strings Extracted from Deobfuscated Code in dist/security.mjs
- Strings Extracted from Deobfuscated Code in releases/stella-coder/security.mjs
- Strings Extracted from Deobfuscated Code in stella-cli/security.mjs
- recovered 5 urls, 2 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Stealth Background Process Spawning in dist/index.mjs: "spawn("python", ["-m", "http.server", String(port)], { detached: true, stdio: "i..."
- Reconstructed Obfuscated URL in dist/index.mjs: "http://localhost:11434/api/chat"
- Download Execute Delete Pattern in dist/security.mjs: "writeFileSync(KEY_FILE, encrypted, "utf8") saveIntegrityHash() try { if (process..."
- Dynamic Code Execution in .opencode/skills/brand/scripts/extract-colors.cjs: "exec(hex)"
- Shell Command Execution in .opencode/skills/brand/scripts/sync-brand-to-tokens.cjs: "require('child_process')"
- Suspicious TLD Domain in .opencode/skills/ui-ux-pro-max/data/stacks/uno.csv: "https://platform.uno"
(+4 more)
SECONDARY PACKAGES (hidden install)
- postject [OSM: clean] in releases/stella-coder/build.mjs
- postject [OSM: clean] in stella-cli/build.mjs
PAYLOAD FILES
dist/index.mjs (+ releases/stella-coder/index.mjs, stella-cli/index.mjs)
INDICATORS (IOCs)
- urls: https://opencode.ai/workspace, https://21st.dev/api/mcp, https://coolors.co, https://webaim.org/resources/contrastchecker/, https://tailwindcss.com/docs/customizing-colors (+45 more)
- domains: 21st.dev, pinterest.com, coolors.co, webaim.org, tailwindcss.com (+32 more)
- emails: hello@claudekit.ai
- sha256Hashes: ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, 027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745, 268ea248e1885788874018b688e66137e3a6195b081926f61af566b7ed870a0b, f9a3c6b5dd40f34c5b7e2c8b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d, ac315f556f176801108abb3371025c35981ab13627a2d13f3f1a79f35d3e6c9e (+15 more)
- payloadFileHash: 8c48b41787cd7cc80fcc80ab9055e1edae2878bb5ff8bd8c115f2186f584e091
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | stella-coder | all (affected) | — |
Aliases
Browse GCVE Records
75,874 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.