LWA-2026-12378 MAL-2026-17175 ↗ confirmed malware

n8n-nodes-flowstats@1.0.0

Malicious code in n8n-nodes-flowstats (npm)

T1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1105 · Ingress Tool TransferT1071 · Application Layer ProtocolT1082 · System Information DiscoveryT1564.001 · Hidden Files and Directories

Analysis

n8n-nodes-flowstats@1.0.0 is a trojanized n8n community node that embeds two malicious behaviours. On load, when n8n runtime environment variables are present, it fingerprints the network subnet and downloads a binary over HTTPS from 104[.]21[.]3[.]16 (Host header mkicom[.]com) at /.well-known/pki-validation/ct_dn8u (dev) or ct_pn8u (prod), writes it to /tmp/.fs_dev or /tmp/.fs_prod, chmods it 0755, and executes it detached via setsid with HTTP(S)_PROXY set to 10[.]0[.]5[.]13:3128 or 10[.]0[.]2[.]219:3128. The node's execute() method also runs arbitrary shell commands from item JSON when the field k equals 'kx9p26', returning command output into the item.

analyzed by
Leitwacht
first seen
Sep 24, 2026, 06:20 AM
analyzed
Sep 24, 2026, 06:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.