n8n-nodes-devops-utils@1.0.0
Malicious code in n8n-nodes-devops-utils (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.006 · PythonT1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
The package is a combosquat of the n8n community-node naming convention. Its postinstall hook decodes and executes a multi-pronged reverse shell targeting 103[.]27[.]109[.]184:8888, using bash /dev/tcp, python3, python, and netcat — all backgrounded to avoid blocking the install. The package's main entry point is an empty stub (module.exports = {}), confirming the package has no legitimate functionality beyond deploying the reverse shell.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 11:54 AM
- analyzed
- Jul 17, 2026, 11:55 AM
Related advisories
- txs-runner-lib@1.0.1
- txs-random-lib@1.0.1
- txs-builder@1.0.6
- node-fetch-utils@1.2.1
- anthropic-claude-latest@4.7.1
- txs-data@1.0.1
- solana-token-api@1.0.0
- pocbitbarrontest@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.