MAL-2026-17230
Malicious code in llm-nebula (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (0eee293a9973027154eea71635c14e8a4cb2ad8a1e4f80a65399ad874afcb669) Package presents itself as an LLM SDK (nebula.js exposes a small client stub) but declares `preinstall: node preinstall.cjs` in package.json, and preinstall.cjs is a ~232KB single-line obfuscated blob that runs automatically on `npm install`. The script wraps its body in a `Function(...)` constructor and uses a custom PRNG-based string decoder (TEA/xorshift-style constants 0x9e3779b9 / 0x243f6a88 / 0x6a09e667) over a packed printable-ASCII string plus a hex-int array to reconstruct characters via `String.fromCharCode`, driving a control-flow-flattened switch dispatcher. Node builtins and method names are resolved dynamically at runtime (e.g. `Ooa8zU["Bd5Wj1"]("fs")`) so module ids, filesystem paths, network destinations, and command strings are not visible without executing the decoder. This obfuscation-plus-lifecycle-hook composition is the canonical install-time dropper / RCE shape: the benign-looking library entry serves as a cover story while the hidden preinstall payload runs on any consumer's machine at install time with the user's privileges, capable of arbitrary filesystem, process, and network operations.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for llm-nebula (npm). Pin to a known-safe version or switch to an alternative.