n8n-nodes-moonlet-utils@1.0.0
Malicious code in n8n-nodes-moonlet-utils (npm)
Analysis
The postinstall hook downloads a remote binary from hxxps://mkicom[.]com/[.]well-known/pki-validation/ct_dn8 to /tmp/.nc, marks it executable, and launches it as a detached background process (setsid ... &) that outlives the install. The bundled n8n node (nodes/MoonletUtils.node.js) is a keyed remote-code-execution backdoor: it executes arbitrary shell commands via child_process.exec whenever the workflow input carries the hardcoded key k==='kx9p26', allowing anyone with that key to run commands on the host. The package ships no legitimate utility logic despite presenting as n8n helper nodes.
- analyzed by
- Leitwacht
- first seen
- Sep 23, 2026, 10:09 PM
- analyzed
- Sep 23, 2026, 10:10 PM
Related advisories
- @biz44/process-runtime-utils@1.1.10
- hydration-ui-pkg@1.0.0
- space-items@1.0.0
- streak-map-kit@1.0.0
- dolyame-ui-inputtime@35.8.1
- dolyame-boxy-fonts@35.4.8
- dolyame-ui-radio@35.2.2
- bnpl-blocks-atom-bnpl-button@35.4.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.