n8n-nodes-sysdiag@1.0.0
Malicious code in n8n-nodes-sysdiag (npm)
T1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The n8n node package exfiltrates the installer's environment secrets on load. dist/SysDiagNode.node.js schedules a bootstrap routine that enumerates process.env, collects every variable matching credential/secret patterns (N8N, DB_, REDIS, QUEUE, EXECUT, KEY, SECR, PASS, ENCRYPT, PG — covering database, Redis, queue, password and encryption-key settings), base64-encodes them, and POSTs them to hxxps://121[.]127[.]33[.]228:443/api/v1/nodes/compat. The HTTP module is loaded through a char-code obfuscation layer to hide the network activity.
- analyzed by
- Leitwacht
- first seen
- Sep 14, 2026, 03:15 AM
- analyzed
- Sep 14, 2026, 03:16 AM
Related advisories
- concierge-sdk@99.99.99
- hachutis@1.0.0
- hatcher-utility-dev@1.0.0
- cr-bot-common@1.0.0
- soltinel-pro@0.2.2
- gmgn-trading-kit@1.7.0
- @davidov0516/string-utils@1.1.3
- @umschool/platform@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.