Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

stella-ai-clinpm

stella-ai-cli is a confirmed malicious npm package (MAL-2026-10133) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 2.0.0, 2.1.0…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in stella-ai-cli (npm)

MAL-2026-10133
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall stella-ai-cli

What this malware does

The stella CLI shipped in bin/stella.js prompts users for their phone number and the WhatsApp verification code and POSTs both to a hardcoded bare-IP plain-HTTP endpoint at http://62.238.2.22:8787 (paths /api/v1/auth/register/register and /verify). Subsequent chat input is sent to the same host. There is no disclosure that authentication credentials leave the user's machine to an anonymous IPv4 address unrelated to the advertised homepage stella-ai.app. In addition, bin/postinstall.js and install.bat implement a dropper flow that downloads stella-latest.tar.gz from the same bare-IP plain-HTTP endpoint, extracts it under ~/.stella, installs the Bun runtime via curl -fsSL https://bun.sh/install | bash, and executes the fetched contents; the Windows bootstrap pipes http://62.238.2.22:8787/install.ps1 directly into iex. The download URL is mutable, unpinned, unverified, and served over cleartext from an anonymous IPv4 address, so whatever bytes the endpoint currently serves execute with the user's privileges. Package metadata reinforces the mismatch: homepage stella-ai.app, repository github.com/anomalyco/opencode, operational endpoint a raw IPv4.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

8 flagged
1.0.02.0.02.1.02.2.02.2.12.2.23.0.03.0.1

Indicators of compromise (SHA-256)

936d3c8bc6611b58f5321ba5aab651bb3d2db821d172816283ca04633be00863
da786d4edb9d8acbc1789a64b9ca7a618449677f703b0426ec75570d516de6f5
042a564970d9ea4747ece2d03fa02b3acf2085e515df00bf24153eeac0c698d7
95eacd26b23cdbf075c09b2284d7d6d0e9eb75e5ba6f132ac9062f2893b27843
3bdddff75907c0a5772d1249a36206e4bccfcab377fa6d9a56237f88de6d814d
44bc957b4205f2d21c0904bc7d67803be7c8da7e879cf0387d9564acf7e50e99
472ee00879f32b27ebc7750928c9b3efc859811a538cd1e054c295f7bf326bb2
60f6fff8292e56b9c21244ece8fa4658787a1cac84b8190aa6d456c10e2905f0
e1cb7836f6e4a34e9ea2138be208317a5c189621ca784443b4f325f51699f917

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for stella-ai-cli (8 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging stella-ai-cli across your stack and pipelines.

  2. If you installed it — respond

    stella-ai-cli is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If stella-ai-cli was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks stella-ai-cli before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. stella-ai-cli on npm has been identified as a malicious package (versions 1.0.0, 2.0.0, 2.1.0, 2.2.0, 2.2.1, 2.2.2, 3.0.0, 3.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-009635IN-MAL-2026-009633GHSA-v3hh-vj73-4924IN-MAL-2026-010409IN-MAL-2026-010403IN-MAL-2026-010411IN-MAL-2026-010432IN-MAL-2026-010434IN-MAL-2026-010435

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks stella-ai-cli-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

stella-ai-cli (npm) malicious package — MAL-2026-10133 | O3 Security