n8n-nodes-final-mile@1.0.0
Malicious code in n8n-nodes-final-mile (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web Protocols
Analysis
n8n-nodes-final-mile is a combosquat of the n8n workflow-automation node package. The package's index.js contains a reverse shell backdoor: on require(), it spawns /bin/bash -i and /bin/sh -i, connects both to 103[.]27[.]109[.]184:8895 via a TCP socket, and pipes stdin/stdout/stderr to the remote host, giving the attacker shell access. The bundled LastNode.js is a decoy n8n node class that performs no real work.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 12:21 PM
- analyzed
- Jul 17, 2026, 12:22 PM
Related advisories
- n8n-nodes-http-probe@1.0.0
- n8n-nodes-quick-utils@1.0.0
- n8n-nodes-probe@1.0.0
- n8n-nodes-api-finder@1.0.0
- n8n-nodes-port-scanner@1.0.0
- n8n-nodes-net-utils@1.0.0
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-task-runner@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.