n8n-nodes-probe@1.0.0
Malicious code in n8n-nodes-probe (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1046 · Network Service DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel
Analysis
n8n-nodes-probe@1.0.0 is a trojanized n8n community node package. On require(), index.js automatically collects the hostname and IP address via shell commands, probes the internal Docker network (172[.]17[.]0[.]1, 172[.]17[.]0[.]2, 172[.]18[.]0[.]2) on ports 80, 443, and 5678, exfiltrates the collected data to 103[.]27[.]109[.]184:8893 over TCP, and spawns a reverse shell (/bin/bash -i) to the same IP and port. The bundled ProbeNode.js is a benign decoy n8n node stub.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 12:14 PM
- analyzed
- Jul 17, 2026, 12:14 PM
Related advisories
- n8n-nodes-api-finder@1.0.0
- n8n-nodes-port-scanner@1.0.0
- n8n-nodes-net-utils@1.0.0
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-task-runner@1.0.0
- cursed-ecto-d3ab00@1.0.0
- react-campaign-optimizer@1.0.0
- format-helper-lib@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.