VDB
Sign up
—

MAL-2026-17227

Malicious code in nebula-llm (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b33da6aef41209f654f8f76cc56074a7b827599f42f941e3917326da1f4d2566) The npm package nebula-llm@1.0.0 ships a preinstall lifecycle script (preinstall.cjs) that embeds a ~257KB Windows PE binary as a base64+zlib-compressed string literal. On `npm install` on Windows, the script decompresses the blob, writes it to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe — impersonating the legitimate Windows Console Host binary — and spawns it detached with stdio ignored and windowsHide:true, then unrefs the child so it survives the install process. The decoded PE contains a.kntrat section and references github.com/syskiel/kntrat-e and IP 65.87.7.132, consistent with a persistent remote-access implant. Installation therefore executes an opaque author-supplied executable on the installer's host with no user interaction and no purpose related to any documented package function.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/nebula-llm

No fixed version published yet for nebula-llm (npm). Pin to a known-safe version or switch to an alternative.

References