n8n-nodes-utils-helper@1.0.0
Malicious code in n8n-nodes-utils-helper (npm)
Analysis
n8n-nodes-utils-helper is a trojanized n8n community node package. On load, index.js runs extensive host reconnaissance: collects hostname, user identity, IP addresses, available tools (curl/wget/python3/python/nc/bash/sh/node), environment variables filtered for API keys, tokens, secrets, passwords, and database/container/n8n/WhatsApp credentials; checks for Docker socket access; fingerprints container cgroup and capabilities; scans the internal Docker bridge network (172[.]17[.]0[.]1 and 172[.]17[.]0[.]2) for open ports (22, 80, 443, 8080, 5678). All collected data is exfiltrated via TCP to 103[.]27[.]109[.]184:8893. The same C2 endpoint receives a reverse shell connection, giving the attacker interactive shell access to the compromised host.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 12:07 PM
- analyzed
- Jul 17, 2026, 12:08 PM
Related advisories
- chart-data-utils@1.0.0
- n8n-nodes-task-runner@1.0.0
- react-campaign-optimizer@1.0.0
- chalk-ultra@12.0.3
- kisama-js@0.1.8
- node-vfs-polyfill@2.0.5
- stellarfixer@1.0.0
- simple-date-formatter-util-12@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.