-= Per source details. Do not edit below this line.=-
The package declares "preinstall": "node preinstall.cjs" in package.json, and preinstall.cjs is a single-line ~187 KB Function("pbeIUC", "…") invocation implementing a custom PRNG plus string-table decoder (numeric constant table, printable-charset string table UclPgF, a Bob-Jenkins-style mixer, and a decoder that reconstructs strings via modular arithmetic against UclPgF.charCodeAt(...)). The file contains no readable logic — its entire payload is an opaque blob that is decoded and handed to the JS engine during npm install. String fragments visible pre-decoding (e.g. F.kI, zehSPTc@y.Ge, vCpP.BB/.i+gUAKa) are placeholder-shaped and only resolve to real hosts/commands after runtime decoding, so the actual install-time behavior and any network destinations are hidden from static inspection. The wrapper module (nebula.js) and package.json declare no native build step, no compilation, and no other legitimate reason for a 187 KB obfuscated preinstall script. This is the canonical obfuscated npm preinstall dropper shape: arbitrary attacker-authored code executes on every installer's machine at npm install time, with intent to evade review deliberately concealed by the string-table + Function-eval loader.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020979",
"import_time": "2026-10-05T03:28:59.329439011Z",
"modified_time": "2026-10-05T03:12:06Z",
"sha256": "b8232ec7756422686c2bce805fc87821e61a5bd9176cdb2fe7c3190fd2b2eae2",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "preinstall.cjs",
"sha256": "9d00e9dc6f5a57695d0782c0633ed94075d753b03974508596c27862b5717ec6",
"tlsh": "f0047bed74c6f2eae856417e2ee26747e48a7436275b06bdb7381c08f9de9503cd2140"
}
],
"package_integrity": [
{
"filename": "api-nebula-1.0.0.tgz",
"hashes": {
"sha1": "373db1acfe11180b3066fa51724d614111580998",
"sha512_sri": "sha512-8bvnhcs9pmMfG8QzA4JSeqgC/t1wqR3BXrMZI76LF9gRZu1rsgPu92wPIOMvgG4B9cU3uokjW5yr02cXaKy0JQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/api-nebula/MAL-2026-17531.json"