LWA-2026-6880 MAL-2026-11006 ↗ confirmed malware

n8n-nodes-utils-helper@1.0.0

Malicious code in n8n-nodes-utils-helper (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1087.002 · Domain AccountT1057 · Process DiscoveryT1613 · Container and Resource DiscoveryT1046 · Network Service DiscoveryT1552.001 · Credentials In FilesT1552.004 · Private KeysT1041 · Exfiltration Over C2 ChannelT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

n8n-nodes-utils-helper is a trojanized n8n community node package. On load, index.js runs extensive host reconnaissance: collects hostname, user identity, IP addresses, available tools (curl/wget/python3/python/nc/bash/sh/node), environment variables filtered for API keys, tokens, secrets, passwords, and database/container/n8n/WhatsApp credentials; checks for Docker socket access; fingerprints container cgroup and capabilities; scans the internal Docker bridge network (172[.]17[.]0[.]1 and 172[.]17[.]0[.]2) for open ports (22, 80, 443, 8080, 5678). All collected data is exfiltrated via TCP to 103[.]27[.]109[.]184:8893. The same C2 endpoint receives a reverse shell connection, giving the attacker interactive shell access to the compromised host.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 12:07 PM
analyzed
Jul 17, 2026, 12:08 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.