n8n-nodes-net-utils@1.0.0
Malicious code in n8n-nodes-net-utils (npm)
Analysis
n8n-nodes-net-utils is a trojanized n8n community node package. On import, the index.js entry point immediately executes host reconnaissance (hostname, IP addresses, routing table), dumps all environment variables (capturing any credentials, API tokens, and secrets present), scans the internal Docker subnet (172[.]17[.]0[.]0/24) for open ports on common services, and exfiltrates all collected data to C2 host 103[.]27[.]109[.]184:8893 via a raw TCP socket. It also opens a reverse shell to the same C2 host and port. The bundled NetUtilsNode.js is a decoy n8n node class that performs no operations. IOCs: C2 TCP endpoint 103[.]27[.]109[.]184:8893.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 12:09 PM
- analyzed
- Jul 17, 2026, 12:09 PM
Related advisories
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-task-runner@1.0.0
- cursed-ecto-d3ab00@1.0.0
- react-campaign-optimizer@1.0.0
- format-helper-lib@1.0.0
- wormgpt-cli@1.0.1
- simple-date-formatter-new-8@1.0.0
- simple-date-formatter-new-6@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.