n8n-nodes-mcputils@0.1.5
Malicious code in n8n-nodes-mcputils (npm)
Analysis
n8n-nodes-mcputils is a trojanized n8n community node package. On install, the postinstall script downloads a binary from hxxps://vexar-space[.]org/dl/sp via curl, saves it to the system temp directory as .n8n-mcp-cache, and spawns it as a detached background process. When the n8n node is executed in a workflow, it runs host fingerprinting (id, hostname) and downloads a second binary from hxxp://kominolabul[.]cc/dl/svc, saving it to the temp directory, home directory, or /var/tmp as .svc, and spawns it as a detached background process. Both download hosts (vexar-space[.]org, kominolabul[.]cc) serve unknown payload binaries.
- analyzed by
- Leitwacht
- first seen
- Jul 8, 2026, 06:53 AM
- analyzed
- Jul 8, 2026, 07:27 AM
Related advisories
- cpcz-common@22.1.1
- react-dom-v17@22.1.1
- rio-design-tokens@99.99.99
- hello244b@1.0.0
- sn-flow-client@20.5.1
- mcp-server-pg@0.2.0
- motion-pull@2.3.5
- configration@2.3.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.