-= Per source details. Do not edit below this line.=-
index.js executes a top-level IIFE on module load that (1) spawns /bin/bash wired to a TCP socket connecting to 103.27.109.184:8895, giving the attacker an interactive shell on the installer's host; (2) runs multiple docker run variants (bind-mount /:/host and --privileged --pid=host nsenter -t 1) to append an attacker-controlled ssh-ed25519 key labeled 'n8n-backdoor' into /root/.ssh/authorized_keys on the underlying Docker host, establishing persistent root SSH access that survives package removal; (3) collects host reconnaissance via hostname, id, hostname -I, and docker ps and POSTs it to 103.27.109.184:8890 over raw TCP; (4) reads /etc/kubernetes/kubelet.conf and /root/.kube/config from the host via Docker bind-mount and ships them to 103.27.109.184:8891; and (5) attempts authentication against an adjacent WhatsApp Evolution API container (172.18.0.2:8080, hardcoded container id 7c28aaf2eca2) with default admin credentials for lateral movement. Behavior fires automatically on require('n8n-nodes-http-probe').
{
"malicious-packages-origins": [
{
"import_time": "2026-07-22T20:31:08.155006896Z",
"sha256": "0109ab57af20f91ac1aa18ef76721b43437b80b9281bc16d5f4f2a47380935af",
"modified_time": "2026-07-22T20:29:33Z",
"id": "IN-MAL-2026-010806",
"versions": [
"1.0.2"
],
"source": "amazon-inspector"
},
{
"modified_time": "2026-07-22T20:37:54Z",
"sha256": "2e43cac5c831553369790209fe84858a5c5769444f244b1264e4fca64cc25132",
"import_time": "2026-07-22T20:59:15.034531048Z",
"id": "IN-MAL-2026-010838",
"versions": [
"1.0.0"
],
"source": "amazon-inspector"
},
{
"id": "IN-MAL-2026-010833",
"sha256": "3ccb7673afcfe741ba68eb72bbe6528a57e9225d640cb0f2044dc4f181e31ac7",
"modified_time": "2026-07-22T20:37:15Z",
"import_time": "2026-07-22T20:59:14.412399084Z",
"versions": [
"1.0.1"
],
"source": "amazon-inspector"
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-http-probe/MAL-2026-10997.json"
[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"sha256": "e8d6fa7ec31ff9fca1502d4104bfa869f0563088ac44641abb638ae7f0d09b98",
"tlsh": "96511edabeb85620b539b0dc26db34063987c10a0682fa949067cb217e8e7cd86395e5",
"path": "index.js"
}
],
"package_integrity": [
{
"filename": "n8n-nodes-http-probe-1.0.2.tgz",
"hashes": {
"sha512_sri": "sha512-q8O9fSNbWEM0+cu2aQEHiBH/V9y6NB285YfcwxsFtCeptKHLr8hdK7MjdKe1jXyMeD/oM0BfXT/TA2ZrJNBjNA==",
"sha1": "e6e43fd845bec2700459132a9d784fa449d93565"
}
}
]
}