Logo
npm

api-nebula@1.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC

Malicious

OSV ID

MAL-2026-17531

Ecosystem

npm

Summary

The package declares "preinstall": "node preinstall.cjs" in package.json, and preinstall.cjs is a single-line ~187 KB Function("pbeIUC", "…") invocation implementing a custom PRNG plus string-table decoder (numeric constant table, printable-charset string table UclPgF, a Bob-Jenkins-style mixer, and a decoder that reconstructs strings via modular arithmetic against UclPgF.charCodeAt(...)). The file contains no readable logic — its entire payload is an opaque blob that is decoded and handed to the JS engine during npm install. String fragments visible pre-decoding (e.g. F.kI, zehSPTc@y.Ge, vCpP.BB/.i+gUAKa) are placeholder-shaped and only resolve to real hosts/commands after runtime decoding, so the actual install-time behavior and any network destinations are hidden from static inspection. The wrapper module (nebula.js) and package.json declare no native build step, no compilation, and no other legitimate reason for a 187 KB obfuscated preinstall script. This is the canonical obfuscated npm preinstall dropper shape: arbitrary attacker-authored code executes on every installer's machine at npm install time, with intent to evade review deliberately concealed by the string-table + Function-eval loader.

Source: amazon-inspector (b8232ec7756422686c2bce805fc87821e61a5bd9176cdb2fe7c3190fd2b2eae2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.