Threat reportSupply ChainTL-2026-3049

NEBULA: Seven Fake AI SDK Packages on npm Install a Windows RAT (Modified KNTRAT) That Needs No DLL

highACTIVE

NEBULA: Seven Fake AI SDK Packages on npm Install a Windows (TL-2026-3049), also tracked as NebulaAI fake SDK campaign, is a high-severity supply-chain compromise, first published 2026-10-08. It is attributed to NEBULA with low confidence, affects npm api-nebula, maps to 14 MITRE ATT&CK techniques (T1027, T1036.005, T1059.007), and is covered by 9 detection rules and 23 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
1NEBULA
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-3049

Threat ID
TL-2026-3049
Also known as
NebulaAI fake SDK campaign, KNTRAT npm campaign
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
NEBULA
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, software-development, ai-ml
Target regions
Global
Detection rules
9
Indicators of compromise
23

Malware and tooling in NEBULA: Seven Fake AI SDK Packages on npm Install a Windows

Malware and tooling: KNTRAT

How NEBULA: Seven Fake AI SDK Packages on npm Install a Windows works

CloudSEK reports a single actor tracked as NEBULA published seven fake 'NebulaAI' SDK packages to npm from four burner accounts. An obfuscated preinstall.cjs dropper writes a modified open-source KNTRAT Windows RAT to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe. The RAT provides HVNC, camera/microphone monitoring via Kernel Streaming, Winlogon Shell persistence and direct NT/win32k syscalls with an empty IAT.

CloudSEK Global Threat Intelligence (published 2026-10-08) attributes a campaign to a single actor tracked as NEBULA. The actor published seven fake AI SDK packages to npm under a 'NebulaAI' lure, using four sequentially named burner accounts (nebulallms, nebulallms2, nebulallms3, nebulallms4). The packages' entry point (nebula.js) is a legitimate-looking client pointed at api.nebulaai.dev. The malicious logic lives in a 'preinstall' lifecycle hook that runs preinstall.cjs, an obfuscated single-line script (about 187 KB in api-nebula) that executes automatically on npm install.

On Windows, the dropper delivers a Windows PE payload either as an inline base64+zlib-encoded blob (about 257 KB, per OpenSSF/OSV advisories for nebula-llm, nebula-sdk and nebulaai-sdk) or by fetching it at install time. The PE is written to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe, masquerading as the Windows Console Host, and launched detached with stdio ignored and windowsHide set, then unref'd so it survives the end of the npm process. nebulajs-api uses a different obfuscation (a custom PRNG-based decoder that reconstructs and runs a hidden payload) with the same install-time execution pattern.

The payload is a customized variant of KNTRAT, an open-source RAT. The decoded PE contains a section named '.kntrat' and references github.com/syskiel/kntrat-e (per OSV MAL-2026-17227); CloudSEK states the repository was private during the campaign and was renamed from kntrat-e to kntrat on 2026-10-06. Reported capabilities: hidden-desktop remote control (HVNC), camera and microphone monitoring via Kernel Streaming, persistence through the Winlogon Shell value, and direct NT and win32k system calls that leave the Import Address Table empty (hence 'needs no DLL'). C2 indicators: IP 65.87.7.132, domain api.nebulaai.dev and user-agent kntrat/0xB15B00B6. The sample suppressed beaconing during a 12-minute sandbox detonation.

Timeline: nebula-sdk, nebulajs-api, nebula-llm and nebulaai-sdk were published and flagged around 2026-09-28 (advisories MAL-2026-17219/17220/17227/17228, reported by Amazon Inspector and others); api-nebula 1.0.0 was categorized as MAL-2026-17531 on 2026-10-05 after days unflagged. At CloudSEK's publication api-nebula and llm-nebula were still downloadable. Only four of the seven package names are corroborated by OSV records; the CloudSEK page names api-nebula and llm-nebula, and the remaining package names, victim counts and download numbers are not stated in available sources. No file hashes of the dropped PE were published in the sources reviewed. No CVEs are involved.

MITRE ATT&CK techniques used in TL-2026-3049

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1564.003 Hide Artifacts: Hidden Window

Execution

T1059.007 Command and Scripting Interpreter: JavaScript; T1106 Native API

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1219 Remote Access Tools

Collection

T1123 Audio Capture; T1125 Video Capture

Initial Access

T1195.002 Supply Chain Compromise: Compromise Software Supply Chain

Persistence

T1547.004 Boot or Logon Autostart Execution: Winlogon Helper DLL

Resource Development

T1583.001 Acquire Infrastructure: Domains

Affected products and versions in NEBULA: Seven Fake AI SDK Packages on npm Install a Windows

  • npm — api-nebula
    Vulnerable versions: 1.0.0
  • npm — nebula-llm
    Vulnerable versions: 1.0.0
  • npm — nebula-sdk
    Vulnerable versions: 1.0.0; 1.0.1
  • npm — nebulaai-sdk
    Vulnerable versions: 1.0.0
  • npm — nebulajs-api
    Vulnerable versions: 1.0.0
  • npm — llm-nebula
  • Microsoft — Windows (hosts running npm install)

Remediation for NEBULA: Seven Fake AI SDK Packages on npm Install a Windows

Immediate actions

  • Block installs of api-nebula, llm-nebula, nebula-llm, nebula-sdk, nebulaai-sdk and nebulajs-api in registry proxies and CI
  • Block and alert on traffic to 65.87.7.132 and api.nebulaai.dev, and on the user-agent kntrat/0xB15B00B6
  • Hunt for %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe and any conhost.exe outside System32
  • Review npm install logs and lockfiles for preinstall.cjs execution from these packages
  • Treat any Windows host that installed these packages as compromised; rotate secrets and credentials from a trusted system

Workarounds

  • Remove the affected package versions and verify persistence (Winlogon Shell) is removed; consider a full reinstall or forensic analysis

Longer-term hardening

  • Enforce npm install --ignore-scripts by default and allowlist packages that need lifecycle scripts
  • Use a package firewall or proxy with malware-feed (OSV/OpenSSF malicious-packages) checks and a minimum package-age policy
  • Alert on Winlogon Shell registry changes and on unsigned binaries launched from user-profile Conhost folders
  • Detect processes with empty import tables that issue direct syscalls and create hidden desktops

Weaknesses (CWE) in NEBULA: Seven Fake AI SDK Packages on npm Install a Windows

CWE-506

Timeline of NEBULA: Seven Fake AI SDK Packages on npm Install a Windows

  • CloudSEK dates deployment of the NEBULA campaign to late September 2026, using four sequential burner npm accounts (nebulallms through nebulallms4).
  • nebula-sdk, nebulajs-api, nebula-llm and nebulaai-sdk are published to npm (OSV/OffSeq publish timestamps 2026-09-28) and flagged as malicious (MAL-2026-17219, -17220, -17227, -17228); nebula-llm and nebulaai-sdk reported by Amazon Inspector.
  • api-nebula 1.0.0 is categorized as malicious (MAL-2026-17531, Amazon Inspector) after being active and unflagged for days.
  • The KNTRAT source repository, private during the campaign, is renamed from kntrat-e to kntrat.
  • CloudSEK reports the RAT suppressed beaconing throughout a 12-minute sandbox detonation.
  • CloudSEK publishes its analysis; api-nebula and llm-nebula are still downloadable from npm at the time of publication.

Sources cited for NEBULA: Seven Fake AI SDK Packages on npm Install a Windows

Detection coverage for TL-2026-3049

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3049 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats