LWA-2026-6881 MAL-2026-11003 ↗ confirmed malware

n8n-nodes-net-utils@1.0.0

Malicious code in n8n-nodes-net-utils (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1046 · Network Service DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 ChannelT1071 · Application Layer Protocol

Analysis

n8n-nodes-net-utils is a trojanized n8n community node package. On import, the index.js entry point immediately executes host reconnaissance (hostname, IP addresses, routing table), dumps all environment variables (capturing any credentials, API tokens, and secrets present), scans the internal Docker subnet (172[.]17[.]0[.]0/24) for open ports on common services, and exfiltrates all collected data to C2 host 103[.]27[.]109[.]184:8893 via a raw TCP socket. It also opens a reverse shell to the same C2 host and port. The bundled NetUtilsNode.js is a decoy n8n node class that performs no operations. IOCs: C2 TCP endpoint 103[.]27[.]109[.]184:8893.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 12:09 PM
analyzed
Jul 17, 2026, 12:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.