NEBULA: Seven Fake AI SDK Packages on npm Install a Windows RAT That Needs No DLL
Description
In late September 2026, seven malicious npm packages impersonating a NebulaAI SDK were deployed to deliver a Windows remote-access trojan (RAT). The RAT uses direct NT and win32k syscalls, avoiding DLL imports, and includes features such as hidden-desktop remote control, camera and microphone monitoring via Kernel Streaming, and persistence through Winlogon Shell. The malware communicates with a command-and-control server at 65.87.7.132 and disguises itself as conhost.exe while employing anti-analysis techniques.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The NEBULA operation involves seven fake npm packages masquerading as NebulaAI SDKs, distributed via four burner accounts and two remaining downloadable packages. Each package contains an obfuscated installation hook that executes a customized KNTRAT variant. This RAT bypasses standard DLL imports by using direct system calls, enabling stealthy operations including hidden virtual network computing (HVNC), kernel streaming for audio/video surveillance, and persistence via Winlogon Shell. The implant communicates with a C2 server at IP 65.87.7.132 using a specific user-agent string and suppresses beaconing during analysis to evade detection.
Potential Impact
The malware enables remote attackers to gain persistent, stealthy control over infected Windows systems, including remote desktop access, audio and video surveillance, and system persistence. This compromises confidentiality, integrity, and availability of affected systems. The supply chain vector via npm packages increases risk of widespread infection among developers and environments relying on these packages.
Defensive Guidance
No official patch or remediation is indicated. Mitigation should focus on removing the malicious npm packages from projects and systems, blocking communication to the identified C2 IP (65.87.7.132) and domains (e.g., api.nebulaai.dev), and scanning for the known file hashes. Users should avoid installing npm packages from untrusted or suspicious sources and verify package authenticity before use.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://cdn.cloudsek.com/cloudsek-blog-pdfs/cloudsek-neb-qhe.pdf"]
- Pulse Id
- 6ac8a46214e2077a0bfe7409
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip65.87.7.132 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainapi.nebulaai.dev | — | |
domainfact-register.md | — | |
domainuberip.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash5222dd57b8859e791a16abcf7f616bbc59f8cf248798c7c8c2ba800f0b52cd8c | — | |
hash8bc90df9b387849338d9c61a8d379cfbb0d70ea576c0e37e1fb07ba164921807 | — | |
hashe99bab7b8bbbde7c821dae4ccfedfd1e608d65c466de9b08037c5ce5f56af3b1 | — | |
hashf0d36ac2d75c81a4c3cbdbf2f717db858f2876e6a1cc74f2d36b729a1dd51a5e | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://api.nebulaai.dev/v2 | — |
Threat ID: 6ac8a6ed2cdf04f6563e8905
Added to database: 10/09/2026, 08:33:49 UTC
Last enriched: 10/09/2026, 08:52:30 UTC
Last updated: 10/09/2026, 18:48:09 UTC
Views: 36
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.