{"id":"MAL-2026-17531","summary":"Malicious code in api-nebula (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b8232ec7756422686c2bce805fc87821e61a5bd9176cdb2fe7c3190fd2b2eae2)\nThe package declares `\"preinstall\": \"node preinstall.cjs\"` in package.json, and preinstall.cjs is a single-line ~187 KB `Function(\"pbeIUC\", \"…\")` invocation implementing a custom PRNG plus string-table decoder (numeric constant table, printable-charset string table `UclPgF`, a Bob-Jenkins-style mixer, and a decoder that reconstructs strings via modular arithmetic against `UclPgF.charCodeAt(...)`). The file contains no readable logic — its entire payload is an opaque blob that is decoded and handed to the JS engine during `npm install`. String fragments visible pre-decoding (e.g. `F.kI`, `zehSPTc@y.Ge`, `vCpP.BB/.i+gUAKa`) are placeholder-shaped and only resolve to real hosts/commands after runtime decoding, so the actual install-time behavior and any network destinations are hidden from static inspection. The wrapper module (nebula.js) and package.json declare no native build step, no compilation, and no other legitimate reason for a 187 KB obfuscated preinstall script. This is the canonical obfuscated npm preinstall dropper shape: arbitrary attacker-authored code executes on every installer's machine at `npm install` time, with intent to evade review deliberately concealed by the string-table + Function-eval loader.\n","modified":"2026-10-05T03:45:04.115753417Z","published":"2026-10-05T03:12:06Z","database_specific":{"malicious-packages-origins":[{"sha256":"b8232ec7756422686c2bce805fc87821e61a5bd9176cdb2fe7c3190fd2b2eae2","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020979","import_time":"2026-10-05T03:28:59.329439011Z","modified_time":"2026-10-05T03:12:06Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/api-nebula/v/1.0.0"}],"affected":[{"package":{"name":"api-nebula","ecosystem":"npm","purl":"pkg:npm/api-nebula"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"preinstall.cjs","sha256":"9d00e9dc6f5a57695d0782c0633ed94075d753b03974508596c27862b5717ec6","tlsh":"f0047bed74c6f2eae856417e2ee26747e48a7436275b06bdb7381c08f9de9503cd2140"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-8bvnhcs9pmMfG8QzA4JSeqgC/t1wqR3BXrMZI76LF9gRZu1rsgPu92wPIOMvgG4B9cU3uokjW5yr02cXaKy0JQ==","sha1":"373db1acfe11180b3066fa51724d614111580998"},"filename":"api-nebula-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/api-nebula/MAL-2026-17531.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}