npm · Malicious package advisory
Malwarenebula-llm
GHSA-5ph8-m4r7-g739
Malicious code in nebula-llm (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (b33da6aef41209f654f8f76cc56074a7b827599f42f941e3917326da1f4d2566) The npm package [email protected] ships a preinstall lifecycle script (preinstall.cjs) that embeds a ~257KB Windows PE binary as a base64+zlib-compressed string literal. On `npm install` on Windows, the script decompresses the blob, writes it to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe — impersonating the legitimate Windows Console Host binary — and spawns it detached with stdio ignored and windowsHide:true, then unrefs the child so it survives the install process. The decoded PE contains a.kntrat section and references github.com/syskiel/kntrat-e and IP 65.87.7.132, consistent with a persistent remote-access implant. Installation therefore executes an opaque author-supplied executable on the installer's host with no user interaction and no purpose related to any documented package function. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/nebula-llm/MAL-2026-17227.json)) **References:** - https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/nebula-llm/MAL-2026-17227.json - https://www.npmjs.com/package/nebula-llm/v/1.0.0 - https://github.com/advisories/GHSA-5ph8-m4r7-g739
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.