LWA-2026-12393 MAL-2026-17228 ↗ confirmed malware

nebulaai-sdk@1.0.0

Malicious code in nebulaai-sdk (npm)

T1059.007 · JavaScriptT1036 · MasqueradingT1204.002 · Malicious File

Analysis

The package's preinstall hook (preinstall.js) embeds a large base64-encoded gzip blob, decompresses it, and writes the resulting binary to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe — a hidden directory that mimics a Windows system path. It then executes that dropped binary detached and hidden (stdio ignored, windowsHide set). The package's main module (nebula.js) is a decoy AI SDK client that is not the real purpose of the package. Installing this package drops and runs an unknown binary on the host.

analyzed by
Leitwacht
first seen
Sep 25, 2026, 06:17 AM
analyzed
Sep 25, 2026, 06:18 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.