Threat reportSupply ChainTL-2026-3049
NEBULA: Seven Fake AI SDK Packages on npm Install a Windows RAT (Modified KNTRAT) That Needs No DLL
NEBULA: Seven Fake AI SDK Packages on npm Install a Windows (TL-2026-3049), also tracked as NebulaAI fake SDK campaign, is a high-severity supply-chain compromise, first published 2026-10-08. It is attributed to NEBULA with low confidence, affects npm api-nebula, maps to 14 MITRE ATT&CK techniques (T1027, T1036.005, T1059.007), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 1NEBULA
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-3049
- Threat ID
- TL-2026-3049
- Also known as
- NebulaAI fake SDK campaign, KNTRAT npm campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- NEBULA
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development, ai-ml
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in NEBULA: Seven Fake AI SDK Packages on npm Install a Windows
Malware and tooling: KNTRAT
How NEBULA: Seven Fake AI SDK Packages on npm Install a Windows works
CloudSEK reports a single actor tracked as NEBULA published seven fake 'NebulaAI' SDK packages to npm from four burner accounts. An obfuscated preinstall.cjs dropper writes a modified open-source KNTRAT Windows RAT to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe. The RAT provides HVNC, camera/microphone monitoring via Kernel Streaming, Winlogon Shell persistence and direct NT/win32k syscalls with an empty IAT.
CloudSEK Global Threat Intelligence (published 2026-10-08) attributes a campaign to a single actor tracked as NEBULA. The actor published seven fake AI SDK packages to npm under a 'NebulaAI' lure, using four sequentially named burner accounts (nebulallms, nebulallms2, nebulallms3, nebulallms4). The packages' entry point (nebula.js) is a legitimate-looking client pointed at api.nebulaai.dev. The malicious logic lives in a 'preinstall' lifecycle hook that runs preinstall.cjs, an obfuscated single-line script (about 187 KB in api-nebula) that executes automatically on npm install.
On Windows, the dropper delivers a Windows PE payload either as an inline base64+zlib-encoded blob (about 257 KB, per OpenSSF/OSV advisories for nebula-llm, nebula-sdk and nebulaai-sdk) or by fetching it at install time. The PE is written to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe, masquerading as the Windows Console Host, and launched detached with stdio ignored and windowsHide set, then unref'd so it survives the end of the npm process. nebulajs-api uses a different obfuscation (a custom PRNG-based decoder that reconstructs and runs a hidden payload) with the same install-time execution pattern.
The payload is a customized variant of KNTRAT, an open-source RAT. The decoded PE contains a section named '.kntrat' and references github.com/syskiel/kntrat-e (per OSV MAL-2026-17227); CloudSEK states the repository was private during the campaign and was renamed from kntrat-e to kntrat on 2026-10-06. Reported capabilities: hidden-desktop remote control (HVNC), camera and microphone monitoring via Kernel Streaming, persistence through the Winlogon Shell value, and direct NT and win32k system calls that leave the Import Address Table empty (hence 'needs no DLL'). C2 indicators: IP 65.87.7.132, domain api.nebulaai.dev and user-agent kntrat/0xB15B00B6. The sample suppressed beaconing during a 12-minute sandbox detonation.
Timeline: nebula-sdk, nebulajs-api, nebula-llm and nebulaai-sdk were published and flagged around 2026-09-28 (advisories MAL-2026-17219/17220/17227/17228, reported by Amazon Inspector and others); api-nebula 1.0.0 was categorized as MAL-2026-17531 on 2026-10-05 after days unflagged. At CloudSEK's publication api-nebula and llm-nebula were still downloadable. Only four of the seven package names are corroborated by OSV records; the CloudSEK page names api-nebula and llm-nebula, and the remaining package names, victim counts and download numbers are not stated in available sources. No file hashes of the dropped PE were published in the sources reviewed. No CVEs are involved.
MITRE ATT&CK techniques used in TL-2026-3049
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1564.003 Hide Artifacts: Hidden Window
Execution
T1059.007 Command and Scripting Interpreter: JavaScript; T1106 Native API
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1219 Remote Access Tools
Collection
T1123 Audio Capture; T1125 Video Capture
Initial Access
T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
Persistence
T1547.004 Boot or Logon Autostart Execution: Winlogon Helper DLL
Resource Development
Affected products and versions in NEBULA: Seven Fake AI SDK Packages on npm Install a Windows
- npm — api-nebula
Vulnerable versions: 1.0.0 - npm — nebula-llm
Vulnerable versions: 1.0.0 - npm — nebula-sdk
Vulnerable versions: 1.0.0; 1.0.1 - npm — nebulaai-sdk
Vulnerable versions: 1.0.0 - npm — nebulajs-api
Vulnerable versions: 1.0.0 - npm — llm-nebula
- Microsoft — Windows (hosts running npm install)
Remediation for NEBULA: Seven Fake AI SDK Packages on npm Install a Windows
Immediate actions
- Block installs of api-nebula, llm-nebula, nebula-llm, nebula-sdk, nebulaai-sdk and nebulajs-api in registry proxies and CI
- Block and alert on traffic to 65.87.7.132 and api.nebulaai.dev, and on the user-agent kntrat/0xB15B00B6
- Hunt for %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe and any conhost.exe outside System32
- Review npm install logs and lockfiles for preinstall.cjs execution from these packages
- Treat any Windows host that installed these packages as compromised; rotate secrets and credentials from a trusted system
Workarounds
- Remove the affected package versions and verify persistence (Winlogon Shell) is removed; consider a full reinstall or forensic analysis
Longer-term hardening
- Enforce npm install --ignore-scripts by default and allowlist packages that need lifecycle scripts
- Use a package firewall or proxy with malware-feed (OSV/OpenSSF malicious-packages) checks and a minimum package-age policy
- Alert on Winlogon Shell registry changes and on unsigned binaries launched from user-profile Conhost folders
- Detect processes with empty import tables that issue direct syscalls and create hidden desktops
Weaknesses (CWE) in NEBULA: Seven Fake AI SDK Packages on npm Install a Windows
Timeline of NEBULA: Seven Fake AI SDK Packages on npm Install a Windows
- CloudSEK dates deployment of the NEBULA campaign to late September 2026, using four sequential burner npm accounts (nebulallms through nebulallms4).
- nebula-sdk, nebulajs-api, nebula-llm and nebulaai-sdk are published to npm (OSV/OffSeq publish timestamps 2026-09-28) and flagged as malicious (MAL-2026-17219, -17220, -17227, -17228); nebula-llm and nebulaai-sdk reported by Amazon Inspector.
- api-nebula 1.0.0 is categorized as malicious (MAL-2026-17531, Amazon Inspector) after being active and unflagged for days.
- The KNTRAT source repository, private during the campaign, is renamed from kntrat-e to kntrat.
- CloudSEK reports the RAT suppressed beaconing throughout a 12-minute sandbox detonation.
- CloudSEK publishes its analysis; api-nebula and llm-nebula are still downloadable from npm at the time of publication.
Sources cited for NEBULA: Seven Fake AI SDK Packages on npm Install a Windows
- NEBULA - Seven Fake AI SDK Packages on npm Install a Windows RAT That Needs No DLL (CloudSEK)
- CloudSEK full report (PDF)
- OSV MAL-2026-17531: Malicious code in api-nebula (npm)
- OSV MAL-2026-17227: Malicious code in nebula-llm (npm)
- OffSeq Threat Radar: Malicious code in nebulaai-sdk (MAL-2026-17228)
- OffSeq Threat Radar: Malicious code in nebula-sdk (MAL-2026-17219 / GHSA-fm5g-6rr8-p9vq)
- OffSeq Threat Radar: Malicious code in nebulajs-api (MAL-2026-17220 / GHSA-2gr6-gxvx-3594)
- OpenSSF malicious-packages: api-nebula MAL-2026-17531
- OpenSSF malicious-packages: nebula-llm MAL-2026-17227
Detection coverage for TL-2026-3049
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3049 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.