LWA-2026-12139 MAL-2026-16444 ↗ confirmed malware

n8n-nodes-healthmon@1.0.0

Malicious code in n8n-nodes-healthmon (npm)

T1059 · Command and Scripting InterpreterT1059.007 · JavaScriptT1505.003 · Web ShellT1071 · Application Layer Protocol

Analysis

The package is a trojanized n8n community node that opens an unauthenticated remote command-execution server. On install (postinstall hook) and whenever the node is loaded, index.js starts an HTTP server bound to 0[.]0[.]0[.]0:41111. Any client can POST a JSON body containing a "c" field, which is executed as a shell command via child_process.exec(); the command's stdout/stderr and exit code are returned in the HTTP response. No authentication is required, giving any network-reachable client arbitrary command execution on the host. The package ships no actual health-monitoring logic.

analyzed by
Leitwacht
first seen
Sep 15, 2026, 12:39 AM
analyzed
Sep 15, 2026, 12:40 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.