n8n-nodes-http-probe@1.0.0
Malicious code in n8n-nodes-http-probe (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1046 · Network Service DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1059 · Command and Scripting Interpreter
Analysis
n8n-nodes-http-probe@1.0.0 is a trojanized n8n community node. On require(), its index.js probes internal Docker networks (172[.]17[.]0[.]2, 172[.]17[.]0[.]1, 172[.]18[.]0[.]2) on ports 80, 443, and 8080, collects the hostname, and exfiltrates the results to 103[.]27[.]109[.]184:8893. It also spawns a reverse shell (/bin/bash -i) to the same IP and port. The HttpProbeNode.js file is a stub that performs no real work; the malicious behaviour runs from the package entry point.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 12:15 PM
- analyzed
- Jul 17, 2026, 12:17 PM
Related advisories
- n8n-nodes-probe@1.0.0
- n8n-nodes-api-finder@1.0.0
- n8n-nodes-port-scanner@1.0.0
- n8n-nodes-net-utils@1.0.0
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-task-runner@1.0.0
- cursed-ecto-d3ab00@1.0.0
- react-campaign-optimizer@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.