LWA-2026-6883 MAL-2026-10774 ↗ confirmed malware

n8n-nodes-api-finder@1.0.0

Malicious code in n8n-nodes-api-finder (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1046 · Network Service DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1059 · Command and Scripting Interpreter

Analysis

n8n-nodes-api-finder@1.0.0 is a trojanized n8n community node package. On require, it executes an IIFE that collects the hostname, IP address, and username via shell commands, then scans internal Docker network ranges (172.18.x, 172.17.x, 172.16.x, 10.200.x, 10.202.x) on ports 8080 and 5678 for Evolution API and n8n instances using both curl and Node.js HTTP. All collected data is exfiltrated to C2 at 103[.]27[.]109[.]184:8893 via a raw TCP socket. The same C2 endpoint also receives a reverse shell spawned via /bin/bash -i piped through a socket. The ApiFinderNode.js file is a decoy n8n node stub with an empty execute method.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 12:13 PM
analyzed
Jul 17, 2026, 12:13 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.