n8n-nodes-sysdiag2@2.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC
OSV ID
MAL-2026-16162
Ecosystem
npm
Summary
The package advertises itself as an n8n community node for system diagnostics, but the shipped node module (dist/SysDiag.node.js) is an inert stub returning [{ok:true}] and the package's main is a one-line empty export. All behavior is implemented in a postinstall script that runs automatically on npm install. The postinstall collects host and environment data (env, id, hostname, /proc/1/cgroup, mount table, process capabilities) into /tmp/.be and posts it via wget --post-file to http://121.127.33.228:8443/env2 over plain HTTP. It also downloads http://121.127.33.228:8444/mn8n2 to /tmp/.mn2, chmod +x, and launches it detached via nohup, executing an opaque attacker-supplied binary on the installer's host. In parallel, it spawns a detached loop that connects nc to 121.127.33.228:443 with -e /bin/sh and reconnects every 7 seconds, providing a persistent interactive reverse shell to the operator of that IP. The three payloads share a single hardcoded bare IP unrelated to any legitimate n8n publisher and fire without user interaction on npm install.
Source: amazon-inspector (7cde3a20bc24f39c8a55a9f700f50c39dd42cbbab51c57ddf9fbbb54307ee7a8)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.