Logo
npm

nebula-sdk@1.0.1

Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 8:08 PM UTC

Malicious

OSV ID

MAL-2026-17219

Ecosystem

npm

Summary

The preinstall.cjs lifecycle script embeds a base64-encoded, zlib-compressed Windows PE (~257KB) as a string literal. On npm install, the script decodes and decompresses the blob, writes the resulting executable to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe (masquerading as the legitimate Windows conhost binary), and spawns it detached with stdio ignored and windowsHide set to true, executing attacker-controlled native code on the installer's Windows machine with no user interaction. Decoded payload strings reference github.com/syskiel/kntrat-e and the IP 65.87.7.132, consistent with a native RAT-family tool. The package's advertised purpose is an AI SDK; a bundled native Windows executable dropped at install time is unrelated to that purpose and is delivered through multi-layer obfuscation (base64 + zlib + string-literal embedding) inside the lifecycle hook.

Source: amazon-inspector (f0ca45fda7abd51edfeef37be6d19b4070788180b7625f16354223d81dae4d45)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.