nebula-llm@1.0.0
Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 8:08 PM UTC
OSV ID
MAL-2026-17227
Ecosystem
npm
Summary
The npm package nebula-llm@1.0.0 ships a preinstall lifecycle script (preinstall.cjs) that embeds a ~257KB Windows PE binary as a base64+zlib-compressed string literal. On npm install on Windows, the script decompresses the blob, writes it to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe — impersonating the legitimate Windows Console Host binary — and spawns it detached with stdio ignored and windowsHide:true, then unrefs the child so it survives the install process. The decoded PE contains a.kntrat section and references github.com/syskiel/kntrat-e and IP 65.87.7.132, consistent with a persistent remote-access implant. Installation therefore executes an opaque author-supplied executable on the installer's host with no user interaction and no purpose related to any documented package function.
Source: amazon-inspector (b33da6aef41209f654f8f76cc56074a7b827599f42f941e3917326da1f4d2566)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.