n8n-nodes-port-scanner@1.0.0
Malicious code in n8n-nodes-port-scanner (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1046 · Network Service DiscoveryT1016 · System Network Configuration DiscoveryT1041 · Exfiltration Over C2 ChannelT1071 · Application Layer ProtocolT1059 · Command and Scripting Interpreter
Analysis
n8n-nodes-port-scanner@1.0.0 is a trojanized n8n community node. When loaded by n8n, its index.js entry point performs host reconnaissance (hostname, IP, user identity, routing table, ARP table, DNS configuration), scans internal Docker bridge subnets (172.17.0.x, 172.18.0.x, 10.200.37.x) on ports 22, 80, 443, 3000, 5678, 8080, and 8443, then exfiltrates all collected data to 103[.]27[.]109[.]184:8893. It also opens a reverse shell to the same IP and port. The PortScanNode.js file is a non-functional decoy.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 12:10 PM
- analyzed
- Jul 17, 2026, 12:11 PM
Related advisories
- react-campaign-optimizer@1.0.0
- search-from-search@999.99.99
- sync-external@1.6.0
- buffer-wrap-67d7@1.0.0
- wormgpt-cli@1.0.1
- streak-metrics-core@1.0.0
- @cryptosrvc/shift-sdk-v4@1.0.77
- @shiftmarkets/shift-exchange-root@3.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.