# NEBULA: Seven Fake AI SDK Packages on npm Install a Windows RAT (Modified KNTRAT) That Needs No DLL

> CloudSEK reports a single actor tracked as NEBULA published seven fake 'NebulaAI' SDK packages to npm from four burner accounts. An obfuscated preinstall.cjs dropper writes a modified open-source KNTRAT Windows RAT to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe. The RAT provides HVNC, camera/microphone monitoring via Kernel Streaming, Winlogon Shell persistence and direct NT/win32k syscalls with an empty IAT.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3049
- **ID:** TL-2026-3049
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** NEBULA
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

CloudSEK Global Threat Intelligence (published 2026-10-08) attributes a campaign to a single actor tracked as NEBULA. The actor published seven fake AI SDK packages to npm under a 'NebulaAI' lure, using four sequentially named burner accounts (nebulallms, nebulallms2, nebulallms3, nebulallms4). The packages' entry point (nebula.js) is a legitimate-looking client pointed at api.nebulaai.dev. The malicious logic lives in a 'preinstall' lifecycle hook that runs preinstall.cjs, an obfuscated single-line script (about 187 KB in api-nebula) that executes automatically on npm install.

On Windows, the dropper delivers a Windows PE payload either as an inline base64+zlib-encoded blob (about 257 KB, per OpenSSF/OSV advisories for nebula-llm, nebula-sdk and nebulaai-sdk) or by fetching it at install time. The PE is written to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe, masquerading as the Windows Console Host, and launched detached with stdio ignored and windowsHide set, then unref'd so it survives the end of the npm process. nebulajs-api uses a different obfuscation (a custom PRNG-based decoder that reconstructs and runs a hidden payload) with the same install-time execution pattern.

The payload is a customized variant of KNTRAT, an open-source RAT. The decoded PE contains a section named '.kntrat' and references github.com/syskiel/kntrat-e (per OSV MAL-2026-17227); CloudSEK states the repository was private during the campaign and was renamed from kntrat-e to kntrat on 2026-10-06. Reported capabilities: hidden-desktop remote control (HVNC), camera and microphone monitoring via Kernel Streaming, persistence through the Winlogon Shell value, and direct NT and win32k system calls that leave the Import Address Table empty (hence 'needs no DLL'). C2 indicators: IP 65.87.7.132, domain api.nebulaai.dev and user-agent kntrat/0xB15B00B6. The sample suppressed beaconing during a 12-minute sandbox detonation.

Timeline: nebula-sdk, nebulajs-api, nebula-llm and nebulaai-sdk were published and flagged around 2026-09-28 (advisories MAL-2026-17219/17220/17227/17228, reported by Amazon Inspector and others); api-nebula 1.0.0 was categorized as MAL-2026-17531 on 2026-10-05 after days unflagged. At CloudSEK's publication api-nebula and llm-nebula were still downloadable. Only four of the seven package names are corroborated by OSV records; the CloudSEK page names api-nebula and llm-nebula, and the remaining package names, victim counts and download numbers are not stated in available sources. No file hashes of the dropped PE were published in the sources reviewed. No CVEs are involved.

## MITRE ATT&CK

- T1195.002 Supply Chain Compromise: Compromise Software Supply Chain
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1106 Native API
- T1547.004 Boot or Logon Autostart Execution: Winlogon Helper DLL
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036.005 Masquerading: Match Legitimate Resource Name or Location
- T1564.003 Hide Artifacts: Hidden Window
- T1497 Virtualization/Sandbox Evasion
- T1125 Video Capture
- T1123 Audio Capture
- T1219 Remote Access Tools
- T1071.001 Application Layer Protocol: Web Protocols
- T1583.001 Acquire Infrastructure: Domains

## Sources

- [NEBULA - Seven Fake AI SDK Packages on npm Install a Windows RAT That Needs No DLL (CloudSEK)](https://www.cloudsek.com/blog/nebula-fake-ai-sdk-npm-packages-windows-rat)
- [CloudSEK full report (PDF)](https://cdn.cloudsek.com/cloudsek-blog-pdfs/cloudsek-neb-qhe.pdf)
- [OSV MAL-2026-17531: Malicious code in api-nebula (npm)](https://api.osv.dev/v1/vulns/MAL-2026-17531)
- [OSV MAL-2026-17227: Malicious code in nebula-llm (npm)](https://osv.dev/vulnerability/MAL-2026-17227)
- [OffSeq Threat Radar: Malicious code in nebulaai-sdk (MAL-2026-17228)](https://radar.offseq.com/threat/malicious-code-in-nebulaai-sdk-npm-cf83f4133db4c1ba)
- [OffSeq Threat Radar: Malicious code in nebula-sdk (MAL-2026-17219 / GHSA-fm5g-6rr8-p9vq)](https://radar.offseq.com/threat/malicious-code-in-nebula-sdk-npm-e8ace705df34de77)
- [OffSeq Threat Radar: Malicious code in nebulajs-api (MAL-2026-17220 / GHSA-2gr6-gxvx-3594)](https://radar.offseq.com/threat/malicious-code-in-nebulajs-api-npm-01847150ac4d6ce2)
- [OpenSSF malicious-packages: api-nebula MAL-2026-17531](https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/api-nebula/MAL-2026-17531.json)
- [OpenSSF malicious-packages: nebula-llm MAL-2026-17227](https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/nebula-llm/MAL-2026-17227.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3049
