< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

npm packages masquerading as AI tools deliver Windows malware

Cybersecurity researchers at CloudSEK have identified a software supply-chain attack targeting developers through the npm registry. A campaign named NEBULA involves malicious packages masquerading as a software development kit for a service called NebulaAI.

Seven malicious packages, including api-nebula and llm-nebula, were used to distribute a Windows remote-access trojan (RAT) known as KNTRAT. The attack utilizes an obfuscated installation script that triggers during the package setup to deploy the malware. Once active, the RAT allows attackers to remotely control desktops, execute commands, and access camera and microphone functions while establishing persistence through Windows logon settings.

Entities

CloudSEK · NebulaAI · TrendAI · UAC-0099 · npm