VDB
GCVE-110-OSM-2026-12670
GCVE-110-OSM-2026-12670
Advisory PublishedCVSS 9.6/10
This package, and the other five packages in this cluster pretend to be related to Nebula AI, but instead deliver a new Windows based malware and RAT named KNTRAT. This malware is an npm supply-chain dropper that abuses preinstall lifecycle scripts to silently decode and launch a Windows PE RAT under %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe, detached and hidden from the user. The RAT connects to 65.87.7.132:443 using a WebSocket-style HTTP upgrade, maintains a bidirectional command channel, and appears capable of spawning or controlling cmd.exe through a named pipe; the package also contains strings suggesting Windows shell persistence. Several package variants use obfuscated installers or misleading AI SDK functionality to conceal the same payload, while the complete native command set and post-handshake protocol remain unresolved.
ENTRY
preinstall.js (install-hook: node preinstall.js)
- Install Hook Executes Local JS File in package.json
The package's `preinstall.js` contains a base64+zlib-encoded 257 KB Windows PE executable. On `npm install` on Windows, the script decodes the blob and writes it to `%LOCALAPPDATA%\Microsoft\Conhost\conhost.exe` — a path and filename that impersonates a legitimate Windows console host binary — then spawns it via `child_process.spawn` with `detached: true`, `stdio: 'ignore'`, and `windowsHide: true`, so execution is silent and survives the npm process. The decoded PE contains a section named `.kntrat` and references the external host `65.87.7.132` and the repository `github.com/syskiel/kntrat-e`, indicating remote command-and-control functionality (RAT-shaped naming). The package has no legitimate SDK functionality visible; the preinstall hook exists solely to stage and run the embedded executable. Installing this package on a Windows host results in full arbitrary code execution under the installing user, with a masqueraded persistent binary staged under LOCALAPPDATA and a C2 endpoint reachable at 65.87.7.132.
DESTINATION
- 1 c2 (urls)
(values recorded in verified_iocs)
OBFUSCATION
- Dynamic Base64 Decoding in preinstall.js: "Buffer.from(base64, 'base64')"
- Base64 Encoded Payload in preinstall.js: "'eJzsfQt4VNW18Dkzk2SA4JlglIgIo0ZLWh8ZQWUEISfMhH3wDEZBRaWKr4iWWgwzEJVKwkwkx2HatMV..."
- Deobfuscation Failed in preinstall.js
ADDITIONAL FINDINGS
- Stealth Background Process Spawning in preinstall.js: "spawn(outputPath, [], { detached: true, stdio: 'ignore', windowsHide: true }"
- Shell Command Execution in preinstall.js: "require('child_process')"
- Silent Process Execution in preinstall.js: "stdio: 'ignore'"
- Detached Child Process Payload in preinstall.js: "spawn(outputPath, [], { detached: true"
PAYLOAD FILES
preinstall.js
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | nebulaai-sdk | all (affected) | — |
Aliases
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.