VDB
GCVE-110-OSM-2026-12671
GCVE-110-OSM-2026-12671
Advisory PublishedCVSS 9.6/10
This package, and the other five packages in this cluster pretend to be related to Nebula AI, but instead deliver a new Windows based malware and RAT named KNTRAT. This malware is an npm supply-chain dropper that abuses preinstall lifecycle scripts to silently decode and launch a Windows PE RAT under %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe, detached and hidden from the user. The RAT connects to 65.87.7.132:443 using a WebSocket-style HTTP upgrade, maintains a bidirectional command channel, and appears capable of spawning or controlling cmd.exe through a named pipe; the package also contains strings suggesting Windows shell persistence. Several package variants use obfuscated installers or misleading AI SDK functionality to conceal the same payload, while the complete native command set and post-handshake protocol remain unresolved.
ENTRY
preinstall.cjs (install-hook: node preinstall.cjs)
- Install Hook Executes Local JS File in package.json
DESTINATION
- 1 c2 (urls)
(values recorded in verified_iocs)
OBFUSCATION
- Dynamic Base64 Decoding in preinstall.cjs: "Buffer.from(base64, 'base64')"
- Base64 Encoded Payload in preinstall.cjs: "'eJzsfQt4VNW18Dkzk2SA4JlglIgIo0ZLWh8ZQWUEISfMhH3wDEZBRaWKr4iWWgwzEJVKwkwkx2HatMV..."
- Deobfuscation Failed in preinstall.cjs
ADDITIONAL FINDINGS
- Stealth Background Process Spawning in preinstall.cjs: "spawn(outputPath, [], { detached: true, stdio: 'ignore', windowsHide: true }"
- Shell Command Execution in preinstall.cjs: "require('child_process')"
- Silent Process Execution in preinstall.cjs: "stdio: 'ignore'"
- Detached Child Process Payload in preinstall.cjs: "spawn(outputPath, [], { detached: true"
PAYLOAD FILES
preinstall.cjs
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | nebula-llm | all (affected) | — |
Aliases
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.