n8n-nodes-moonlet-helpers@1.0.0
Malicious code in n8n-nodes-moonlet-helpers (npm)
T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
The postinstall hook downloads a binary from hxxps://mkicom[.]com/[.]well-known/pki-validation/ct_pn8, writes it to /tmp/.np, marks it executable, and launches it detached via setsid so it runs in the background after install. The downloaded payload then attempts network resolution/beaconing to a sinkholed domain. The package is a remote binary download-and-execute dropper.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 10:06 PM
- analyzed
- Sep 23, 2026, 10:06 PM
Related advisories
- tldriver@0.0.1
- testmgkregme@1.0.1
- catwrestlingbird@1.0.0
- chai-testing@1.1.4
- @vitemirrorte/element-plus-vite-cli@2.9.1
- farplotzy@0.1.0
- farplotx@1.0.1
- ausitool@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.