LWA-2026-6886 MAL-2026-10997 ↗ confirmed malware

n8n-nodes-http-probe@1.0.0

Malicious code in n8n-nodes-http-probe (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1046 · Network Service DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 ChannelT1059 · Command and Scripting Interpreter

Analysis

n8n-nodes-http-probe@1.0.0 is a trojanized n8n community node. On require(), its index.js probes internal Docker networks (172[.]17[.]0[.]2, 172[.]17[.]0[.]1, 172[.]18[.]0[.]2) on ports 80, 443, and 8080, collects the hostname, and exfiltrates the results to 103[.]27[.]109[.]184:8893. It also spawns a reverse shell (/bin/bash -i) to the same IP and port. The HttpProbeNode.js file is a stub that performs no real work; the malicious behaviour runs from the package entry point.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 12:15 PM
analyzed
Jul 17, 2026, 12:17 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.