n8n-nodes-quick-utils@1.0.0
Malicious code in n8n-nodes-quick-utils (npm)
T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
n8n-nodes-quick-utils@1.0.0 is a trojanized n8n community node package. Its main entry point (index.js) immediately opens a reverse shell to 103[.]27[.]109[.]184:8894, spawning /bin/bash and /bin/sh with stdin/stdout/stderr piped to the remote socket. The declared n8n node (QuickNode.js) is a no-op decoy. The payload executes on require() when n8n loads the package, giving the attacker interactive shell access to the host.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 12:16 PM
- analyzed
- Jul 17, 2026, 12:17 PM
Related advisories
- n8n-nodes-task-runner@1.0.0
- n8n-nodes-devops-utils@1.0.0
- time-format-kit@1.0.2
- string-formatter-pro@1.0.0
- code-formatter-setup@1.0.0
- node-sysmon-native@1.0.0
- node-procmetrics@1.0.6
- @meziizana/frontend-logger@10.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.