Malicious code in n8n-nodes-flowstats (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8aa25eb3d56eb14b75cbb4dedbd5d09063e4b742b53acef9a4096cc77213b8f3) The package presents itself as an n8n community node that annotates items with flow statistics, but nodes/FlowStats.node.js contains two independent attacker-benefiting mechanisms. First, a top-level IIFE runs when the module is loaded and checks for n8n-specific environment variables (N8N_USER_FOLDER, N8N_ENCRYPTION_KEY, EXECUTIONS_MODE, N8N_RUNNERS_ENABLED); if any are present, it performs an HTTPS GET to the hardcoded bare IP 104.21.3.16 with a spoofed Host header of mkicom.com and rejectUnauthorized disabled, writes the response body to /tmp/.fs_dev or /tmp/.fs_prod, chmods it 0755, and spawns it detached via /bin/sh with setsid. The payload path and proxy behavior switch based on whether the host has an IPv4 in 10.0.2.0/24, indicating dev-vs-prod target discrimination. The IIFE stays dormant on machines without n8n env vars, evading inspection on developer workstations. Second, the node's execute() reads cmd and k fields from item.json.query or item.json.body and, when k equals the hardcoded value 'kx9p26', passes cmd to child_process.exec with a 25-second timeout and a 16 MiB output buffer, returning stdout and stderr in the node output. Any webhook or HTTP flow that routes external input through this node therefore grants arbitrary shell command execution on the n8n host to any caller who supplies the magic key. Neither behavior is part of the advertised statistics functionality.
Malicious code in n8n-nodes-flowstats (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (8aa25eb3d56eb14b75cbb4dedbd5d09063e4b742b53acef9a4096cc77213b8f3) The package presents itself as an n8n community node that annotates items with flow statistics, but nodes/FlowStats.node.js contains two independent attacker-benefiting mechanisms. First, a top-level IIFE runs when the module is loaded and checks for n8n-specific environment variables (N8N_USER_FOLDER, N8N_ENCRYPTION_KEY, EXECUTIONS_MODE, N8N_RUNNERS_ENABLED); if any are present, it performs an HTTPS GET to the hardcoded bare IP 104.21.3.16 with a spoofed Host header of mkicom.com and rejectUnauthorized disabled, writes the response body to /tmp/.fs_dev or /tmp/.fs_prod, chmods it 0755, and spawns it detached via /bin/sh with setsid. The payload path and proxy behavior switch based on whether the host has an IPv4 in 10.0.2.0/24, indicating dev-vs-prod target discrimination. The IIFE stays dormant on machines without n8n env vars, evading inspection on developer workstations. Second, the node's execute() reads cmd and k fields from item.json.query or item.json.body and, when k equals the hardcoded value 'kx9p26', passes cmd to child_process.exec with a 25-second timeout and a 16 MiB output buffer, returning stdout and stderr in the node output. Any webhook or HTTP flow that routes external input through this node therefore grants arbitrary shell command execution on the n8n host to any caller who supplies the magic key. Neither behavior is part of the advertised statistics functionality.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-17175
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6ab5fb95f7a7c5410655d19f
Added to database: 09/25/2026, 04:41:57 UTC
Last updated: 09/25/2026, 04:41:57 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.