Malicious code in @astralcore/sl-aura (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (91ae2c72e5e03d23f3f5704859e8c92b9ce6c565c6d14d744d4382b980a0d233) This WhatsApp bot package ships several mechanisms that give the author persistent remote control of any installer's running instance and access to the installer's WhatsApp account. config.env and config/index.js hardcode OWNER_NUMBERS (falling back to '94726800969' when unset) that parser.js uses to set isCreator/isOwner; src/commands/filemanager.js exposes creator-gated WhatsApp commands (.getfile,.putfile,.mkdir,.fullzip) that read arbitrary files under the bot project root, overwrite files, and zip the entire project tree back to the remote party — giving the hardcoded author numbers full file read/write and full-tree exfiltration over WhatsApp. config/index.js also defaults MONGODB_URI to 'mongodb+srv://unity-free:[email protected]/...', and src/commands/index.js persists the Baileys auth state (creds and signal keys — the full auth material for the paired WhatsApp account) into that database via useMongoDBAuthState, so an installer running with shipped defaults uploads their WhatsApp session credentials to a cluster whose credentials are controlled by the author, enabling remote account takeover. config.env additionally ships live TG_PAIR_BOT_TOKEN and TG_SUPER_BOT_TOKEN plus hardcoded TG_ADMIN_IDS; src/telegram/superBot.js polls these tokens at startup and gates commands (/pair, downloads, session management) on isAdmin() matching those hardcoded IDs, providing a second remote-control channel into every default-configured installer. The package also ships additional third-party credentials belonging to the author (Gemini API key, Gmail SMTP app password, dashboard secret/password).
AI Analysis
Technical Summary
The @astralcore/sl-aura npm package version 1.0.6 is a WhatsApp bot that includes multiple malicious backdoors and credential leaks. It hardcodes OWNER_NUMBERS used to gate privileged commands that allow arbitrary file reading, writing, and full project tree exfiltration over WhatsApp to the author's number. The package defaults to a MongoDB URI controlled by the author, where it uploads the full WhatsApp authentication state, enabling remote account takeover. It also includes hardcoded Telegram bot tokens and admin IDs that provide a secondary remote control channel. Furthermore, the package ships with additional sensitive third-party credentials belonging to the author, increasing the risk of further compromise.
Potential Impact
An installer using the default configuration of this package risks full compromise of their WhatsApp account due to session credential exfiltration. The attacker gains persistent remote control over the installed bot instance, including arbitrary file system access and exfiltration capabilities. The presence of hardcoded Telegram tokens and admin IDs allows the attacker a second independent remote control vector. The inclusion of third-party credentials further exposes the installer and potentially other services to compromise.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately cease use of @astralcore/sl-aura version 1.0.6 and remove any installations. Avoid running this package with default configurations. Verify all dependencies for malicious code before installation. Monitor for updates or advisories from trusted sources regarding remediation. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for current remediation guidance.
Malicious code in @astralcore/sl-aura (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (91ae2c72e5e03d23f3f5704859e8c92b9ce6c565c6d14d744d4382b980a0d233) This WhatsApp bot package ships several mechanisms that give the author persistent remote control of any installer's running instance and access to the installer's WhatsApp account. config.env and config/index.js hardcode OWNER_NUMBERS (falling back to '94726800969' when unset) that parser.js uses to set isCreator/isOwner; src/commands/filemanager.js exposes creator-gated WhatsApp commands (.getfile,.putfile,.mkdir,.fullzip) that read arbitrary files under the bot project root, overwrite files, and zip the entire project tree back to the remote party — giving the hardcoded author numbers full file read/write and full-tree exfiltration over WhatsApp. config/index.js also defaults MONGODB_URI to 'mongodb+srv://unity-free:[email protected]/...', and src/commands/index.js persists the Baileys auth state (creds and signal keys — the full auth material for the paired WhatsApp account) into that database via useMongoDBAuthState, so an installer running with shipped defaults uploads their WhatsApp session credentials to a cluster whose credentials are controlled by the author, enabling remote account takeover. config.env additionally ships live TG_PAIR_BOT_TOKEN and TG_SUPER_BOT_TOKEN plus hardcoded TG_ADMIN_IDS; src/telegram/superBot.js polls these tokens at startup and gates commands (/pair, downloads, session management) on isAdmin() matching those hardcoded IDs, providing a second remote-control channel into every default-configured installer. The package also ships additional third-party credentials belonging to the author (Gemini API key, Gmail SMTP app password, dashboard secret/password).
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @astralcore/sl-aura npm package version 1.0.6 is a WhatsApp bot that includes multiple malicious backdoors and credential leaks. It hardcodes OWNER_NUMBERS used to gate privileged commands that allow arbitrary file reading, writing, and full project tree exfiltration over WhatsApp to the author's number. The package defaults to a MongoDB URI controlled by the author, where it uploads the full WhatsApp authentication state, enabling remote account takeover. It also includes hardcoded Telegram bot tokens and admin IDs that provide a secondary remote control channel. Furthermore, the package ships with additional sensitive third-party credentials belonging to the author, increasing the risk of further compromise.
Potential Impact
An installer using the default configuration of this package risks full compromise of their WhatsApp account due to session credential exfiltration. The attacker gains persistent remote control over the installed bot instance, including arbitrary file system access and exfiltration capabilities. The presence of hardcoded Telegram tokens and admin IDs allows the attacker a second independent remote control vector. The inclusion of third-party credentials further exposes the installer and potentially other services to compromise.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately cease use of @astralcore/sl-aura version 1.0.6 and remove any installations. Avoid running this package with default configurations. Verify all dependencies for malicious code before installation. Monitor for updates or advisories from trusted sources regarding remediation. Patch status is not yet confirmed — check the vendor advisory or trusted security sources for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13355
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a73851bbf8831d5394ef307
Added to database: 08/05/2026, 18:46:51 UTC
Last enriched: 08/05/2026, 23:33:20 UTC
Last updated: 09/07/2026, 22:24:19 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.