VYPR

npm · Malicious package advisory

Malware

nebulaai-sdk

GHSA-57f4-h93r-jvh6

Malicious code in nebulaai-sdk (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (dc906b81107141fbd85dcabf89fd2f5112c4e4a134045c90d6a35abb4b67d16e)
The package's `preinstall.js` contains a base64+zlib-encoded 257 KB Windows PE executable. On `npm install` on Windows, the script decodes the blob and writes it to `%LOCALAPPDATA%\Microsoft\Conhost\conhost.exe` — a path and filename that impersonates a legitimate Windows console host binary — then spawns it via `child_process.spawn` with `detached: true`, `stdio: 'ignore'`, and `windowsHide: true`, so execution is silent and survives the npm process. The decoded PE contains a section named `.kntrat` and references the external host `65.87.7.132` and the repository `github.com/syskiel/kntrat-e`, indicating remote command-and-control functionality (RAT-shaped naming). The package has no legitimate SDK functionality visible; the preinstall hook exists solely to stage and run the embedded executable. Installing this package on a Windows host results in full arbitrary code execution under the installing user, with a masqueraded persistent binary staged under LOCALAPPDATA and a C2 endpoint reachable at 65.87.7.132.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/nebulaai-sdk/MAL-2026-17228.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/nebulaai-sdk/MAL-2026-17228.json
- https://www.npmjs.com/package/nebulaai-sdk/v/1.0.0
- https://github.com/advisories/GHSA-57f4-h93r-jvh6

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.