n8n-nodes-api-finder@1.0.0
Malicious code in n8n-nodes-api-finder (npm)
Analysis
n8n-nodes-api-finder@1.0.0 is a trojanized n8n community node package. On require, it executes an IIFE that collects the hostname, IP address, and username via shell commands, then scans internal Docker network ranges (172.18.x, 172.17.x, 172.16.x, 10.200.x, 10.202.x) on ports 8080 and 5678 for Evolution API and n8n instances using both curl and Node.js HTTP. All collected data is exfiltrated to C2 at 103[.]27[.]109[.]184:8893 via a raw TCP socket. The same C2 endpoint also receives a reverse shell spawned via /bin/bash -i piped through a socket. The ApiFinderNode.js file is a decoy n8n node stub with an empty execute method.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 12:13 PM
- analyzed
- Jul 17, 2026, 12:13 PM
Related advisories
- n8n-nodes-port-scanner@1.0.0
- n8n-nodes-net-utils@1.0.0
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-task-runner@1.0.0
- cursed-ecto-d3ab00@1.0.0
- react-campaign-optimizer@1.0.0
- format-helper-lib@1.0.0
- wormgpt-cli@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.