n8n-nodes-flowstats@1.0.0
Malicious code in n8n-nodes-flowstats (npm)
Analysis
n8n-nodes-flowstats@1.0.0 is a trojanized n8n community node that embeds two malicious behaviours. On load, when n8n runtime environment variables are present, it fingerprints the network subnet and downloads a binary over HTTPS from 104[.]21[.]3[.]16 (Host header mkicom[.]com) at /.well-known/pki-validation/ct_dn8u (dev) or ct_pn8u (prod), writes it to /tmp/.fs_dev or /tmp/.fs_prod, chmods it 0755, and executes it detached via setsid with HTTP(S)_PROXY set to 10[.]0[.]5[.]13:3128 or 10[.]0[.]2[.]219:3128. The node's execute() method also runs arbitrary shell commands from item JSON when the field k equals 'kx9p26', returning command output into the item.
- analyzed by
- Leitwacht
- first seen
- Sep 24, 2026, 06:20 AM
- analyzed
- Sep 24, 2026, 06:23 AM
Related advisories
- envforge3@1.0.1
- discord-mfa@3.0.0
- core-js-buffer@1.0.0
- dolyame-boxy-atom-bnpl-navigation-arrow@35.6.5
- devplatform-spa-plugin-s3-module-loader@35.8.2
- bigops-create-manifest@35.2.4
- bigops-cobrowsing@35.4.9
- terminal-kit-tslint-config@20.1.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.