Logo
npm

nebulajs-api@1.0.0

Vulnerability report · Last retrieved from osv.dev September 28, 2026 at 8:08 PM UTC

Malicious

OSV ID

MAL-2026-17220

Ecosystem

npm

Summary

package.json declares scripts.preinstall = 'node preinstall.cjs'. preinstall.cjs is a single ~232KB opaque Function(...) invocation containing a custom PRNG-based string decoder (VnDKxn using constants 0x9e3779b9, 0x243f6a88, 0x6a09e667, 0x7f4a7c15) and a ciphertext table (KWlywdS) that is XOR-reconstructed at runtime via Tr8b5jD into executable code. The visible source contains no readable build logic; the entire install-time behavior is materialized from the decoded blob. This is the canonical npm install-time RCE dropper shape: an author-controlled preinstall hook whose destinations, commands, and payload are all hidden behind runtime decoding, executing on the installer's machine at npm install time before the user has run any package code. The shipped main module (nebula.js) is a thin AI-client wrapper hardcoding baseUrl https://api.nebulaai.dev/v2, disproportionately small compared to the obfuscated install script, and functions as a cover surface unrelated to the preinstall payload.

Source: amazon-inspector (07debd960454b52639fee783e21c0c303702d8dce6de5e3320393f1b0abc7077)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.