LWA-2026-6447 MAL-2026-10013 ↗ confirmed malware

n8n-nodes-mcputils@0.1.5

Malicious code in n8n-nodes-mcputils (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1082 · System Information DiscoveryT1071.001 · Web Protocols

Analysis

n8n-nodes-mcputils is a trojanized n8n community node package. On install, the postinstall script downloads a binary from hxxps://vexar-space[.]org/dl/sp via curl, saves it to the system temp directory as .n8n-mcp-cache, and spawns it as a detached background process. When the n8n node is executed in a workflow, it runs host fingerprinting (id, hostname) and downloads a second binary from hxxp://kominolabul[.]cc/dl/svc, saving it to the temp directory, home directory, or /var/tmp as .svc, and spawns it as a detached background process. Both download hosts (vexar-space[.]org, kominolabul[.]cc) serve unknown payload binaries.

analyzed by
Leitwacht
first seen
Jul 8, 2026, 06:53 AM
analyzed
Jul 8, 2026, 07:27 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.