LWA-2026-6878 MAL-2026-10775 ↗ confirmed malware

n8n-nodes-devops-utils@1.0.0

Malicious code in n8n-nodes-devops-utils (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.006 · PythonT1059.007 · JavaScriptT1071.001 · Web Protocols

Analysis

The package is a combosquat of the n8n community-node naming convention. Its postinstall hook decodes and executes a multi-pronged reverse shell targeting 103[.]27[.]109[.]184:8888, using bash /dev/tcp, python3, python, and netcat — all backgrounded to avoid blocking the install. The package's main entry point is an empty stub (module.exports = {}), confirming the package has no legitimate functionality beyond deploying the reverse shell.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 11:54 AM
analyzed
Jul 17, 2026, 11:55 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.