Back
Adversary Intelligence
Table of Content
Vikas Kundu
A naturally curious mind driven by the need to understand how things work and how to make them better. Passionate about learning, experimenting, and exploring new ideas across technology and security.
No items found.

Executive Summary

In late September 2026, a single actor deployed a series of malicious npm packages posing as a "NebulaAI" software development kit to deliver a Windows remote-access trojan. CloudSEK tracks this activity under the moniker NEBULA. The operation spans seven identified packages distributed across four sequential burner accounts (nebulallms, nebulallms2, nebulallms3, nebulallms4). Among these, api-nebula and llm-nebula remain downloadable on the registry. Notably, api-nebula was active and unflagged for days prior to its formal categorization as MAL-2026-17531 on 5 October 2026, yet it continues to be installable. Each package couples a convincing AI client facade with a hidden, obfuscated installation hook that executes the primary malicious logic.

While individual feed entries document these drops in isolation detailing the install script, masqueraded console executable, and KNTRAT payload they miss the broader operational link: a single actor using a four-account burner sequence to distribute a fake AI SDK. The underlying RAT operates exclusively through direct NT and win32k syscalls, bypassing standard DLL imports and leaving an empty Import Address Table (IAT). Its feature set comprises hidden-desktop remote control (HVNC), Kernel Streaming for camera and microphone monitoring, and Winlogon Shell persistence. The source repository for the RAT remained private during the campaign, only going public after its conclusion (renamed from kntrat-e to kntrat on 6 October 2026). The package serves as the lure; the execution rests within the installation hook. The imported entry point, nebula.js, functions as a legitimate-looking client pointing to api.nebulaai.dev. The actual threat resides in preinstall.cjs, an obfuscated dropper triggered during npm installation. It writes an executable payload to %LOCALAPPDATA%\Microsoft\Conhost\conhost.exe masquerading as the legitimate Windows console host using two delivery methods: an embedded inline payload (base64 and zlib encoded) or an install-time network request. The deployed binary is a customized variant of KNTRAT, an open-source remote-access tool configured to communicate with 65.87.7.132 using the user-agent kntrat/0xB15B00B6. Static analysis of the package revealed these details, as the implant suppressed beaconing during a twelve-minute sandbox detonation, consistent with embedded anti-analysis provisions.

Security teams should immediately restrict the active packages and block infrastructure associated with the campaign. Specifically, prevent installs of api-nebula and llm-nebula, restrict network communication to 65.87.7.132, and implement detection logic for the conhost drop location, custom user-agent, named-pipe constructions, and hidden-desktop artifacts. 

Click Here To Read Full Report

Related Blogs