AI Developer Tools Turned Malware Traps

CloudSEK researchers have uncovered NEBULA, a malicious npm supply-chain campaign involving seven fake AI SDK packages distributed through four attacker-controlled accounts. The packages deploy a modified Windows remote-access trojan (RAT) capable of stealthy surveillance and remote control.

More concerningly, two malicious packages remained downloadable on npm as of October 8, despite being flagged as malicious.

Key findings:

  • 7 malicious packages, 4 publisher accounts: CloudSEK linked seven packages to a single operator using four sequential disposable npm accounts.
  • Flagged, yet still downloadable: api-nebula and llm-nebula remained installable as of October 8. One package operated for days before receiving a formal malware advisory.
  • Stealthy RAT bypasses conventional DLL-based detection: The modified KNTRAT malware uses direct Windows system calls and an empty Import Address Table, undermining import-based security detection.
  • Invisible remote access and surveillance: Source-code analysis confirms hidden-desktop control, camera and microphone access, remote shell execution, and persistence at every user logon.
  • Convincing AI SDK disguise: The packages contain plausible AI client code, while obfuscated installation scripts secretly deploy the malware. The apparent SDK endpoint does not resolve.
  • 162,464 npm packages scanned: CloudSEK’s YARA analysis of available npm archives from September 25–27 identified only the known campaign packages, with no false positives in the scanned dataset.

An important technical finding: The recovered implant did not beacon during more than 12 minutes of controlled testing, consistent with anti-analysis protections. Its capabilities were established through analysis of the recovered binary and the subsequently published KNTRAT source code. No successful victim compromise was confirmed.

Why this matters: The campaign demonstrates how attackers can exploit the growing demand for AI developer tools to introduce malware through trusted software development workflows, potentially exposing developer workstations and corporate environments.

Full research report, technical analysis and indicators of compromise:

https://www.cloudsek.com/blog/nebula-fake-ai-sdk-npm-packages-windows-rat

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading