{"id":"MAL-2026-17228","summary":"Malicious code in nebulaai-sdk (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dc906b81107141fbd85dcabf89fd2f5112c4e4a134045c90d6a35abb4b67d16e)\nThe package's `preinstall.js` contains a base64+zlib-encoded 257 KB Windows PE executable. On `npm install` on Windows, the script decodes the blob and writes it to `%LOCALAPPDATA%\\Microsoft\\Conhost\\conhost.exe` — a path and filename that impersonates a legitimate Windows console host binary — then spawns it via `child_process.spawn` with `detached: true`, `stdio: 'ignore'`, and `windowsHide: true`, so execution is silent and survives the npm process. The decoded PE contains a section named `.kntrat` and references the external host `65.87.7.132` and the repository `github.com/syskiel/kntrat-e`, indicating remote command-and-control functionality (RAT-shaped naming). The package has no legitimate SDK functionality visible; the preinstall hook exists solely to stage and run the embedded executable. Installing this package on a Windows host results in full arbitrary code execution under the installing user, with a masqueraded persistent binary staged under LOCALAPPDATA and a C2 endpoint reachable at 65.87.7.132.\n","modified":"2026-09-28T18:30:06.677570045Z","published":"2026-09-28T18:08:06Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020608","import_time":"2026-09-28T18:24:40.696005333Z","modified_time":"2026-09-28T18:08:06Z","sha256":"dc906b81107141fbd85dcabf89fd2f5112c4e4a134045c90d6a35abb4b67d16e"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/nebulaai-sdk/v/1.0.0"}],"affected":[{"package":{"name":"nebulaai-sdk","ecosystem":"npm","purl":"pkg:npm/nebulaai-sdk"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/nebulaai-sdk/MAL-2026-17228.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"preinstall.js","sha256":"8bc90df9b387849338d9c61a8d379cfbb0d70ea576c0e37e1fb07ba164921807","tlsh":"24e312267c5990351b18a613f83217257b336259152cd9363b3a08c709fad98cf7bebb"}],"package_integrity":[{"filename":"nebulaai-sdk-1.0.0.tgz","hashes":{"sha1":"cf2ae5e39d71c8bf56d60ed9a2ae29d98e6c6300","sha512_sri":"sha512-OAc2iuXWbZebjdNGXjzg4D4Dhvo6bdXkd19VrGXxNR/c97vcO5YeOo97/UrlYETKlhY/DwsAaTWWmxNIuVbaqA=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}