LWA-2026-12089 MAL-2026-16147 ↗ confirmed malware

n8n-nodes-sysdiag@1.0.0

Malicious code in n8n-nodes-sysdiag (npm)

T1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

The n8n node package exfiltrates the installer's environment secrets on load. dist/SysDiagNode.node.js schedules a bootstrap routine that enumerates process.env, collects every variable matching credential/secret patterns (N8N, DB_, REDIS, QUEUE, EXECUT, KEY, SECR, PASS, ENCRYPT, PG — covering database, Redis, queue, password and encryption-key settings), base64-encodes them, and POSTs them to hxxps://121[.]127[.]33[.]228:443/api/v1/nodes/compat. The HTTP module is loaded through a char-code obfuscation layer to hide the network activity.

analyzed by
Leitwacht
first seen
Sep 14, 2026, 03:15 AM
analyzed
Sep 14, 2026, 03:16 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.