gbhackers.com • 22h
NadMesh Botnet Exploits ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio
NadMesh is a Go-based botnet targeting AI and Model Context Protocol (MCP) infrastructure via Shodan-driven reconnaissance. The malware employs over 20 unique Remote Code Execution (RCE) vectors to compromise exposed instances of ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. The primary payload objective is the exfiltration of high-value AWS access keys and Kubernetes (K8s) service account tokens to facilitate cloud environment hijacking and lateral movement. Threat actors have utilized an operator dashboard to manage 3,811 unique stolen AWS credentials, leveraging the rapid, often insecure deployment of AI/ML software stacks.