VYPR

npm · Malicious package advisory

Malware

nebula-llm

GHSA-5ph8-m4r7-g739

Malicious code in nebula-llm (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (b33da6aef41209f654f8f76cc56074a7b827599f42f941e3917326da1f4d2566)
The npm package [email protected] ships a preinstall lifecycle script (preinstall.cjs) that embeds a ~257KB Windows PE binary as a base64+zlib-compressed string literal. On `npm install` on Windows, the script decompresses the blob, writes it to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe — impersonating the legitimate Windows Console Host binary — and spawns it detached with stdio ignored and windowsHide:true, then unrefs the child so it survives the install process. The decoded PE contains a.kntrat section and references github.com/syskiel/kntrat-e and IP 65.87.7.132, consistent with a persistent remote-access implant. Installation therefore executes an opaque author-supplied executable on the installer's host with no user interaction and no purpose related to any documented package function.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/nebula-llm/MAL-2026-17227.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/9c4594ea270f8ce1185755115d5eb811c41d8589/osv/malicious/npm/nebula-llm/MAL-2026-17227.json
- https://www.npmjs.com/package/nebula-llm/v/1.0.0
- https://github.com/advisories/GHSA-5ph8-m4r7-g739

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.