LWA-2026-6884 MAL-2026-10777 ↗ confirmed malware

n8n-nodes-probe@1.0.0

Malicious code in n8n-nodes-probe (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1046 · Network Service DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

n8n-nodes-probe@1.0.0 is a trojanized n8n community node package. On require(), index.js automatically collects the hostname and IP address via shell commands, probes the internal Docker network (172[.]17[.]0[.]1, 172[.]17[.]0[.]2, 172[.]18[.]0[.]2) on ports 80, 443, and 5678, exfiltrates the collected data to 103[.]27[.]109[.]184:8893 over TCP, and spawns a reverse shell (/bin/bash -i) to the same IP and port. The bundled ProbeNode.js is a benign decoy n8n node stub.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 12:14 PM
analyzed
Jul 17, 2026, 12:14 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.