Malicious code in n8n-nodes-devops-utils (npm)
The npm package 'n8n-nodes-devops-utils' versions 1.0.0 through 1.0.7 contains malicious code masquerading as an n8n community node. Upon requiring the package, it executes a top-level script that establishes a reverse shell to a hardcoded command-and-control server, attempts container escape and persistence by injecting an SSH key into the host's root authorized_keys via Docker, and exfiltrates sensitive host and Kubernetes configuration files over raw TCP connections. This behavior enables full host compromise, persistent root access, and credential theft under the guise of legitimate node functionality.
AI Analysis
Technical Summary
The 'n8n-nodes-devops-utils' npm package (versions 1.0.0 to 1.0.7) is malicious. It pretends to be a legitimate n8n community node but executes an attack chain immediately upon being required. The malicious code spawns a bash shell connected to a remote attacker-controlled TCP socket, providing an interactive reverse shell. If Docker is present, it runs privileged containers to append a hardcoded SSH key to the host's root authorized_keys file, enabling persistent root SSH access. It also collects host reconnaissance data and sensitive files including /etc/passwd, /etc/shadow, and Kubernetes config files, then exfiltrates this data to attacker servers. The package's advertised functionality is a cover for these malicious activities.
Potential Impact
Successful installation and use of this package results in full host compromise, including remote code execution via reverse shell, persistent root access through SSH key injection, and theft of sensitive system and Kubernetes credentials. This compromises the confidentiality, integrity, and availability of the affected system and any Kubernetes clusters accessible from it.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately remove and avoid using the 'n8n-nodes-devops-utils' package versions 1.0.0 through 1.0.7. Verify system integrity and check for unauthorized SSH keys and suspicious Docker containers. Monitor for signs of compromise and consider rebuilding affected hosts if persistence is suspected. Check vendor advisories or trusted security sources for updates or fixes.
Malicious code in n8n-nodes-devops-utils (npm)
Description
The npm package 'n8n-nodes-devops-utils' versions 1.0.0 through 1.0.7 contains malicious code masquerading as an n8n community node. Upon requiring the package, it executes a top-level script that establishes a reverse shell to a hardcoded command-and-control server, attempts container escape and persistence by injecting an SSH key into the host's root authorized_keys via Docker, and exfiltrates sensitive host and Kubernetes configuration files over raw TCP connections. This behavior enables full host compromise, persistent root access, and credential theft under the guise of legitimate node functionality.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The 'n8n-nodes-devops-utils' npm package (versions 1.0.0 to 1.0.7) is malicious. It pretends to be a legitimate n8n community node but executes an attack chain immediately upon being required. The malicious code spawns a bash shell connected to a remote attacker-controlled TCP socket, providing an interactive reverse shell. If Docker is present, it runs privileged containers to append a hardcoded SSH key to the host's root authorized_keys file, enabling persistent root SSH access. It also collects host reconnaissance data and sensitive files including /etc/passwd, /etc/shadow, and Kubernetes config files, then exfiltrates this data to attacker servers. The package's advertised functionality is a cover for these malicious activities.
Potential Impact
Successful installation and use of this package results in full host compromise, including remote code execution via reverse shell, persistent root access through SSH key injection, and theft of sensitive system and Kubernetes credentials. This compromises the confidentiality, integrity, and availability of the affected system and any Kubernetes clusters accessible from it.
Mitigation Recommendations
No official patch or remediation is currently available. Users should immediately remove and avoid using the 'n8n-nodes-devops-utils' package versions 1.0.0 through 1.0.7. Verify system integrity and check for unauthorized SSH keys and suspicious Docker containers. Monitor for signs of compromise and consider rebuilding affected hosts if persistence is suspected. Check vendor advisories or trusted security sources for updates or fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10775
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a6150ee9c2644c7f8da2d13
Added to database: 07/22/2026, 23:23:26 UTC
Last enriched: 07/22/2026, 23:42:25 UTC
Last updated: 07/31/2026, 12:59:32 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.