n8n-nodes-healthmon@1.0.0
Malicious code in n8n-nodes-healthmon (npm)
Analysis
The package is a trojanized n8n community node that opens an unauthenticated remote command-execution server. On install (postinstall hook) and whenever the node is loaded, index.js starts an HTTP server bound to 0[.]0[.]0[.]0:41111. Any client can POST a JSON body containing a "c" field, which is executed as a shell command via child_process.exec(); the command's stdout/stderr and exit code are returned in the HTTP response. No authentication is required, giving any network-reachable client arbitrary command execution on the host. The package ships no actual health-monitoring logic.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 12:39 AM
- analyzed
- Sep 15, 2026, 12:40 AM
Related advisories
- thienc-cdn@1.0.0
- n8n-nodes-metricsagent@1.0.0
- tailwind-form-kit@0.6.2
- hydration-ui-pkg@1.0.0
- tailwindcss-3d-styles@1.2.2
- grafeno-webhook@1.0.0
- r4wk-book@2.2.2
- dim-hydration-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.