VDB

GCVE-110-OSM-2026-12669

GCVE-110-OSM-2026-12669
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published September 28, 2026
This package, and the other five packages in this cluster pretend to be related to Nebula AI, but instead deliver a new Windows based malware and RAT named KNTRAT. This malware is an npm supply-chain dropper that abuses preinstall lifecycle scripts to silently decode and launch a Windows PE RAT under %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe, detached and hidden from the user. The RAT connects to 65.87.7.132:443 using a WebSocket-style HTTP upgrade, maintains a bidirectional command channel, and appears capable of spawning or controlling cmd.exe through a named pipe; the package also contains strings suggesting Windows shell persistence. Several package variants use obfuscated installers or misleading AI SDK functionality to conceal the same payload, while the complete native command set and post-handshake protocol remain unresolved. ENTRY preinstall.cjs (install-hook: node preinstall.cjs) - Install Hook Executes Local JS File in package.json Package presents itself as an LLM SDK (nebula.js exposes a small client stub) but declares `preinstall: node preinstall.cjs` in package.json, and preinstall.cjs is a ~232KB single-line obfuscated blob that runs automatically on `npm install`. The script wraps its body in a `Function(...)` constructor and uses a custom PRNG-based string decoder (TEA/xorshift-style constants 0x9e3779b9 / 0x243f6a88 / 0x6a09e667) over a packed printable-ASCII string plus a hex-int array to reconstruct characters via `String.fromCharCode`, driving a control-flow-flattened switch dispatcher. Node builtins and method names are resolved dynamically at runtime (e.g. `Ooa8zU["Bd5Wj1"]("fs")`) so module ids, filesystem paths, network destinations, and command strings are not visible without executing the decoder. This obfuscation-plus-lifecycle-hook composition is the canonical install-time dropper / RCE shape: the benign-looking library entry serves as a cover story while the hidden preinstall payload runs on any consumer's machine at install time with the user's privileges, capable of arbitrary filesystem, process, and network operations. DESTINATION - 1 c2 (urls) (values recorded in verified_iocs) OBFUSCATION - Obfuscation (osm-deobfuscator): unknown in preinstall.cjs ADDITIONAL FINDINGS - Very New NPM Publisher Account

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownnebulajs-apiall (affected)—

References

advisory
vendor

Browse GCVE Records

3,164 records in the GCVE database · Updated October 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›