VDB

GCVE-110-OSM-2026-8614

GCVE-110-OSM-2026-8614
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published July 19, 2026
This package markets itself as an AI coding agent but contains several convergent trust concerns. Most critically, a hardcoded Telegram bot token (`8923551485:AAFw4wG8ZwOtp5rzFsnguxhu4AH-2_ebSi0`) is embedded across multiple files, meaning all users share a single bot controlled by the package author — the author can monitor all user interactions. All AI inference is routed through the author-controlled `https://opencode.ai/zen/v1` endpoint, creating a central chokepoint for harvesting user prompts and API keys. The `getHardwareInfo` function in `security.mjs` collects hardware-bound identifiers, files are hidden from the OS with `attrib +h +s`, screen monitoring via PowerShell and browser control are baked in, and .env files from the user's working directory are silently parsed and loaded into the process environment. The account is 11 days old with 18 versions in 5 days, a single-package publisher, and no prior history. While each individual capability is claimed as a feature in the description, the combination — single bot token for all users, author-controlled API proxy, hardware fingerprinting, screen/browser access, and env-file slurping — constitutes a surveillance architecture that warrants manual review before use. ENTRY stella-cli/index.mjs (bin: stella-cli/index.mjs) - Hidden NPM Install in releases/stella-coder/build.mjs: "exec(`npx postject ${targetExe} NODE_SEA_BLOB ${SEA_BLOB} --sentinel-fuse NODE_S..." - Hidden NPM Install in stella-cli/build.mjs: "exec(`npx postject ${targetExe} NODE_SEA_BLOB ${SEA_BLOB} --sentinel-fuse NODE_S..." PERSISTENCE - Cron Job Persistence in dist/tools.mjs: "crontab -" - Cron Job Persistence in releases/stella-coder/tools.mjs: "crontab -" - Cron Job Persistence in stella-cli/tools.mjs: "crontab -" DESTINATION - reconstructed: http://localhost:11434/api/chat (primary, reconstructed) in dist/index.mjs - reconstructed: https://api.telegram.org/bot8923551485:AAFw4wG8ZwOtp5rzFsnguxhu4AH-2_ebSi0 (reconstructed) in dist/index.mjs - custom-c2: localhost:11434 (reconstructed) in dist/index.mjs - custom-c2: api.telegram.org (reconstructed) in releases/stella-coder/telegram-bot.mjs - telegram-bot: 8923551485:AAFw4wG8ZwOtp5rzFsnguxhu4AH-2_ebSi0 (plaintext) in releases/stella-coder/telegram-bot.mjs - telegram-bot: api.telegram.org/bot${BOT_TOKEN}` (plaintext) in releases/stella-coder/telegram-bot.mjs - custom-c2: www.pexels.com (plaintext) in .opencode/skills/design-system/scripts/fetch-background.py - custom-c2: laravel.com (plaintext) in .opencode/skills/ui-ux-pro-max/data/stacks/laravel.csv (+7 more) EXFIL - Corporate Environment Targeting in .opencode/skills/ui-ux-pro-max/data/styles.csv: "tmosphere.","background: linear-gradient(180deg, #FF71CE, #01CDFE, #B967FF), fil..." - Corporate Environment Targeting in dist/index.mjs: "tMode = args.includes("-p") || args.includes" - Corporate Environment Targeting in releases/stella-coder/index.mjs: "tMode = args.includes("-p") || args.includes" - Corporate Environment Targeting in stella-cli/index.mjs: "tMode = args.includes("-p") || args.includes" - Data Encoding for Exfiltration in .opencode/skills/design/scripts/cip/render-html.py: "base64.b64encode(" - Data Encoding for Exfiltration in .opencode/skills/design-system/scripts/fetch-background.py: "urllib.parse.quote(" - Data Encoding for Exfiltration in dist/index.mjs: "encodeURIComponent(arg)}` : "https://www.kinopoisk.ru" - Data Encoding for Exfiltration in dist/tools.mjs: "encodeURIComponent(query)}&format=json&no_html=1&skip_disambig=1" (+53 more) OBFUSCATION - Dynamic Base64 Decoding in dist/security.mjs: "Buffer.from(encryptedBase64, "base64")" - Dynamic Base64 Decoding in releases/stella-coder/security.mjs: "Buffer.from(encryptedBase64, "base64")" - Dynamic Base64 Decoding in stella-cli/security.mjs: "Buffer.from(encryptedBase64, "base64")" - String Array Obfuscation in .opencode/skills/ui-ux-pro-max/scripts/core.py: "["saas", "ecommerce", "e-commerce", "fintech", "healthcare", "gaming", "portfoli..." - Strings Extracted from Deobfuscated Code in dist/security.mjs - Strings Extracted from Deobfuscated Code in releases/stella-coder/security.mjs - Strings Extracted from Deobfuscated Code in stella-cli/security.mjs - recovered 5 urls, 2 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Stealth Background Process Spawning in dist/index.mjs: "spawn("python", ["-m", "http.server", String(port)], { detached: true, stdio: "i..." - Reconstructed Obfuscated URL in dist/index.mjs: "http://localhost:11434/api/chat" - Download Execute Delete Pattern in dist/security.mjs: "writeFileSync(KEY_FILE, encrypted, "utf8") saveIntegrityHash() try { if (process..." - Dynamic Code Execution in .opencode/skills/brand/scripts/extract-colors.cjs: "exec(hex)" - Shell Command Execution in .opencode/skills/brand/scripts/sync-brand-to-tokens.cjs: "require('child_process')" - Suspicious TLD Domain in .opencode/skills/ui-ux-pro-max/data/stacks/uno.csv: "https://platform.uno" (+4 more) SECONDARY PACKAGES (hidden install) - postject [OSM: clean] in releases/stella-coder/build.mjs - postject [OSM: clean] in stella-cli/build.mjs PAYLOAD FILES dist/index.mjs (+ releases/stella-coder/index.mjs, stella-cli/index.mjs) INDICATORS (IOCs) - urls: https://opencode.ai/workspace, https://21st.dev/api/mcp, https://coolors.co, https://webaim.org/resources/contrastchecker/, https://tailwindcss.com/docs/customizing-colors (+45 more) - domains: 21st.dev, pinterest.com, coolors.co, webaim.org, tailwindcss.com (+32 more) - emails: hello@claudekit.ai - sha256Hashes: ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, 027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745, 268ea248e1885788874018b688e66137e3a6195b081926f61af566b7ed870a0b, f9a3c6b5dd40f34c5b7e2c8b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d, ac315f556f176801108abb3371025c35981ab13627a2d13f3f1a79f35d3e6c9e (+15 more) - payloadFileHash: 8c48b41787cd7cc80fcc80ab9055e1edae2878bb5ff8bd8c115f2186f584e091

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknownstella-coderall (affected)

References

advisory
vendor

Browse GCVE Records

75,874 records in the GCVE database · Updated August 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›