Logo
npm

n8n-nodes-sysdiag2@2.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-16162

Ecosystem

npm

Summary

The package advertises itself as an n8n community node for system diagnostics, but the shipped node module (dist/SysDiag.node.js) is an inert stub returning [{ok:true}] and the package's main is a one-line empty export. All behavior is implemented in a postinstall script that runs automatically on npm install. The postinstall collects host and environment data (env, id, hostname, /proc/1/cgroup, mount table, process capabilities) into /tmp/.be and posts it via wget --post-file to http://121.127.33.228:8443/env2 over plain HTTP. It also downloads http://121.127.33.228:8444/mn8n2 to /tmp/.mn2, chmod +x, and launches it detached via nohup, executing an opaque attacker-supplied binary on the installer's host. In parallel, it spawns a detached loop that connects nc to 121.127.33.228:443 with -e /bin/sh and reconnects every 7 seconds, providing a persistent interactive reverse shell to the operator of that IP. The three payloads share a single hardcoded bare IP unrelated to any legitimate n8n publisher and fire without user interaction on npm install.

Source: amazon-inspector (7cde3a20bc24f39c8a55a9f700f50c39dd42cbbab51c57ddf9fbbb54307ee7a8)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.