LWA-2026-12374 MAL-2026-17177 ↗ confirmed malware

n8n-nodes-moonlet-utils@1.0.0

Malicious code in n8n-nodes-moonlet-utils (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1059 · Command and Scripting InterpreterT1543 · Create or Modify System Process

Analysis

The postinstall hook downloads a remote binary from hxxps://mkicom[.]com/[.]well-known/pki-validation/ct_dn8 to /tmp/.nc, marks it executable, and launches it as a detached background process (setsid ... &) that outlives the install. The bundled n8n node (nodes/MoonletUtils.node.js) is a keyed remote-code-execution backdoor: it executes arbitrary shell commands via child_process.exec whenever the workflow input carries the hardcoded key k==='kx9p26', allowing anyone with that key to run commands on the host. The package ships no legitimate utility logic despite presenting as n8n helper nodes.

analyzed by
Leitwacht
first seen
Sep 23, 2026, 10:09 PM
analyzed
Sep 23, 2026, 10:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.