Logo
npm

nebulaai-sdk@1.0.0

Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 8:08 PM UTC

Malicious

OSV ID

MAL-2026-17228

Ecosystem

npm

Summary

The package's preinstall.js contains a base64+zlib-encoded 257 KB Windows PE executable. On npm install on Windows, the script decodes the blob and writes it to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe — a path and filename that impersonates a legitimate Windows console host binary — then spawns it via child_process.spawn with detached: true, stdio: 'ignore', and windowsHide: true, so execution is silent and survives the npm process. The decoded PE contains a section named .kntrat and references the external host 65.87.7.132 and the repository github.com/syskiel/kntrat-e, indicating remote command-and-control functionality (RAT-shaped naming). The package has no legitimate SDK functionality visible; the preinstall hook exists solely to stage and run the embedded executable. Installing this package on a Windows host results in full arbitrary code execution under the installing user, with a masqueraded persistent binary staged under LOCALAPPDATA and a C2 endpoint reachable at 65.87.7.132.

Source: amazon-inspector (dc906b81107141fbd85dcabf89fd2f5112c4e4a134045c90d6a35abb4b67d16e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.