{"id":"MAL-2026-17227","summary":"Malicious code in nebula-llm (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b33da6aef41209f654f8f76cc56074a7b827599f42f941e3917326da1f4d2566)\nThe npm package nebula-llm@1.0.0 ships a preinstall lifecycle script (preinstall.cjs) that embeds a ~257KB Windows PE binary as a base64+zlib-compressed string literal. On `npm install` on Windows, the script decompresses the blob, writes it to %LOCALAPPDATA%\\Microsoft\\Conhost\\conhost.exe — impersonating the legitimate Windows Console Host binary — and spawns it detached with stdio ignored and windowsHide:true, then unrefs the child so it survives the install process. The decoded PE contains a.kntrat section and references github.com/syskiel/kntrat-e and IP 65.87.7.132, consistent with a persistent remote-access implant. Installation therefore executes an opaque author-supplied executable on the installer's host with no user interaction and no purpose related to any documented package function.\n","modified":"2026-09-28T18:30:05.546871351Z","published":"2026-09-28T18:07:36Z","database_specific":{"malicious-packages-origins":[{"sha256":"b33da6aef41209f654f8f76cc56074a7b827599f42f941e3917326da1f4d2566","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020605","import_time":"2026-09-28T18:24:40.194359216Z","modified_time":"2026-09-28T18:07:36Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/nebula-llm/v/1.0.0"}],"affected":[{"package":{"name":"nebula-llm","ecosystem":"npm","purl":"pkg:npm/nebula-llm"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"preinstall.cjs","sha256":"8bc90df9b387849338d9c61a8d379cfbb0d70ea576c0e37e1fb07ba164921807","tlsh":"24e312267c5990351b18a613f83217257b336259152cd9363b3a08c709fad98cf7bebb"}],"package_integrity":[{"filename":"nebula-llm-1.0.0.tgz","hashes":{"sha1":"032b6edad3b60be8102d88680b33f5c1a600f4c2","sha512_sri":"sha512-yA376+kosqW6rFrXJalk3pXFXCvpBNopJm/Rf1Jr7Ltk7F7YV8p3EVAV+pdWcmO1APU48UJPviUqpajDHQ74Lg=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/nebula-llm/MAL-2026-17227.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}