LWA-2026-12373 MAL-2026-17176 ↗ confirmed malware

n8n-nodes-moonlet-helpers@1.0.0

Malicious code in n8n-nodes-moonlet-helpers (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

The postinstall hook downloads a binary from hxxps://mkicom[.]com/[.]well-known/pki-validation/ct_pn8, writes it to /tmp/.np, marks it executable, and launches it detached via setsid so it runs in the background after install. The downloaded payload then attempts network resolution/beaconing to a sinkholed domain. The package is a remote binary download-and-execute dropper.

analyzed by
Leitwacht
first seen
Sep 23, 2026, 10:06 PM
analyzed
Sep 23, 2026, 10:06 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.