MAL-2026-17531

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/api-nebula/MAL-2026-17531.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17531
Published
2026-10-05T03:12:06Z
Modified
2026-10-05T03:45:04Z
Summary
Malicious code in api-nebula (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (b8232ec7756422686c2bce805fc87821e61a5bd9176cdb2fe7c3190fd2b2eae2)

The package declares "preinstall": "node preinstall.cjs" in package.json, and preinstall.cjs is a single-line ~187 KB Function("pbeIUC", "…") invocation implementing a custom PRNG plus string-table decoder (numeric constant table, printable-charset string table UclPgF, a Bob-Jenkins-style mixer, and a decoder that reconstructs strings via modular arithmetic against UclPgF.charCodeAt(...)). The file contains no readable logic — its entire payload is an opaque blob that is decoded and handed to the JS engine during npm install. String fragments visible pre-decoding (e.g. F.kI, zehSPTc@y.Ge, vCpP.BB/.i+gUAKa) are placeholder-shaped and only resolve to real hosts/commands after runtime decoding, so the actual install-time behavior and any network destinations are hidden from static inspection. The wrapper module (nebula.js) and package.json declare no native build step, no compilation, and no other legitimate reason for a 187 KB obfuscated preinstall script. This is the canonical obfuscated npm preinstall dropper shape: arbitrary attacker-authored code executes on every installer's machine at npm install time, with intent to evade review deliberately concealed by the string-table + Function-eval loader.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020979",
            "import_time":  "2026-10-05T03:28:59.329439011Z",
            "modified_time":  "2026-10-05T03:12:06Z",
            "sha256":  "b8232ec7756422686c2bce805fc87821e61a5bd9176cdb2fe7c3190fd2b2eae2",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / api-nebula

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "preinstall.cjs",
            "sha256":  "9d00e9dc6f5a57695d0782c0633ed94075d753b03974508596c27862b5717ec6",
            "tlsh":  "f0047bed74c6f2eae856417e2ee26747e48a7436275b06bdb7381c08f9de9503cd2140"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "api-nebula-1.0.0.tgz",
            "hashes":  {
                "sha1":  "373db1acfe11180b3066fa51724d614111580998",
                "sha512_sri":  "sha512-8bvnhcs9pmMfG8QzA4JSeqgC/t1wqR3BXrMZI76LF9gRZu1rsgPu92wPIOMvgG4B9cU3uokjW5yr02cXaKy0JQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/api-nebula/MAL-2026-17531.json"