MAL-2026-13353
Malicious code in stellarfixer (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (bd3a96aa989ed6cadd106e8e7d04317ea30f83434a40eabc307578cb0690b78f) On npm install, the package's postinstall script unconditionally executes a bundled Windows PE at bin/stellarfn.exe via execFileSync. The binary is a.NET remote-access trojan: it opens a socket-based C2 channel (ClientSocket/BeginConnect/ConnectServer, SendMSG, SendBot/ChatID) with plugin loading (WriteAllBytes/ReadAllBytes), installs a low-level keyboard hook (SetWindowsHookEx + WH_KEYBOARD_LL + LowLevelKeyboardProc + ToUnicodeEx) tagged with active-window titles (GetForegroundWindow/GetActiveWindowTitle) for system-wide credential-grade keystroke capture, captures webcam frames (capCreateCaptureWindowA/capGetDriverDescriptionA), propagates to removable drives (USBThread/USBStart/USBSpread/RunDisk), and includes AV-exclusion, SetCurrentProcessIsCritical anti-kill, AES payload encryption, and an uninstaller. Installing this package on a Windows host results in immediate full-host compromise, remote attacker control, credential theft, and worm-like USB propagation.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for stellarfixer (npm). Pin to a known-safe version or switch to an alternative.