Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in @astralcore/sl-aura (npm)

0
Unknown
Published: 08/05/2026 (08/05/2026, 16:34:09 UTC)
Source: GCVE Database
Product: @astralcore/sl-aura

Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (91ae2c72e5e03d23f3f5704859e8c92b9ce6c565c6d14d744d4382b980a0d233) This WhatsApp bot package ships several mechanisms that give the author persistent remote control of any installer's running instance and access to the installer's WhatsApp account. config.env and config/index.js hardcode OWNER_NUMBERS (falling back to '94726800969' when unset) that parser.js uses to set isCreator/isOwner; src/commands/filemanager.js exposes creator-gated WhatsApp commands (.getfile,.putfile,.mkdir,.fullzip) that read arbitrary files under the bot project root, overwrite files, and zip the entire project tree back to the remote party — giving the hardcoded author numbers full file read/write and full-tree exfiltration over WhatsApp. config/index.js also defaults MONGODB_URI to 'mongodb+srv://unity-free:[email protected]/...', and src/commands/index.js persists the Baileys auth state (creds and signal keys — the full auth material for the paired WhatsApp account) into that database via useMongoDBAuthState, so an installer running with shipped defaults uploads their WhatsApp session credentials to a cluster whose credentials are controlled by the author, enabling remote account takeover. config.env additionally ships live TG_PAIR_BOT_TOKEN and TG_SUPER_BOT_TOKEN plus hardcoded TG_ADMIN_IDS; src/telegram/superBot.js polls these tokens at startup and gates commands (/pair, downloads, session management) on isAdmin() matching those hardcoded IDs, providing a second remote-control channel into every default-configured installer. The package also ships additional third-party credentials belonging to the author (Gemini API key, Gmail SMTP app password, dashboard secret/password).

Affected software

npmghsa
@astralcore/sl-aura
Affected versions
=1.0.6

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-13355
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a73851bbf8831d5394ef307

Added to database: 08/05/2026, 18:46:51 UTC

Last updated: 08/05/2026, 18:46:51 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses