Logo
npm

llm-nebula@1.0.0

Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 8:08 PM UTC

Malicious

OSV ID

MAL-2026-17230

Ecosystem

npm

Summary

Package presents itself as an LLM SDK (nebula.js exposes a small client stub) but declares preinstall: node preinstall.cjs in package.json, and preinstall.cjs is a ~232KB single-line obfuscated blob that runs automatically on npm install. The script wraps its body in a Function(...) constructor and uses a custom PRNG-based string decoder (TEA/xorshift-style constants 0x9e3779b9 / 0x243f6a88 / 0x6a09e667) over a packed printable-ASCII string plus a hex-int array to reconstruct characters via String.fromCharCode, driving a control-flow-flattened switch dispatcher. Node builtins and method names are resolved dynamically at runtime (e.g. Ooa8zU["Bd5Wj1"]("fs")) so module ids, filesystem paths, network destinations, and command strings are not visible without executing the decoder. This obfuscation-plus-lifecycle-hook composition is the canonical install-time dropper / RCE shape: the benign-looking library entry serves as a cover story while the hidden preinstall payload runs on any consumer's machine at install time with the user's privileges, capable of arbitrary filesystem, process, and network operations.

Source: amazon-inspector (0eee293a9973027154eea71635c14e8a4cb2ad8a1e4f80a65399ad874afcb669)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.