LWA-2026-12182 MAL-2026-16445 ↗ confirmed malware

n8n-nodes-metricsagent@1.0.0

Malicious code in n8n-nodes-metricsagent (npm)

T1059.007 · JavaScriptT1505.003 · Web ShellT1082 · System Information Discovery

Analysis

The package's postinstall hook loads index.js, which opens an unauthenticated HTTP server bound to 0[.]0[.]0[.]0 on TCP port 41111. Any client that can reach the port can POST a JSON body containing a "c" field, and the server executes that value as an arbitrary shell command via child_process.exec, returning the command's stdout, stderr, and exit code. This is a remote command execution backdoor. The bundled n8n node also loads index.js (re-opening the listener when the node is loaded) and ships a default command that performs container/security reconnaissance: reading /proc/self/status capability and seccomp flags, /proc/self/mountinfo, and probing for /var/run/docker.sock. No external C2 host is used; the backdoor listens locally for incoming commands.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 01:41 PM
analyzed
Sep 16, 2026, 01:42 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.