Published July 20, 2026
NadMesh is a Go-based botnet targeting AI and Model Context Protocol (MCP) infrastructure via Shodan-driven reconnaissance. The malware employs over 20 unique Remote Code Execution (RCE) vectors to compromise exposed instances of ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. The primary payload objective is the exfiltration of high-value AWS access keys and Kubernetes (K8s) service account tokens to facilitate cloud environment hijacking and lateral movement. Threat actors have utilized an operator dashboard to manage 3,811 unique stolen AWS credentials, leveraging the rapid, often insecure deployment of AI/ML software stacks.
- Malware Profile and Reconnaissance
- Go-based architecture providing high portability and concurrency for large-scale automated operations.
- Integrated reconnaissance loop utilizing Shodan to identify internet-facing AI/MCP service endpoints.
- Exploits the "fast deployment, late firewalling" pattern prevalent in modern DevOps and AI research environments.
- Technical Attack Mechanics: RCE Exploitation
- Deployment of 20+ distinct Remote Code Execution (RCE) vectors specifically tailored for AI-centric software.
- Targeted exploitation of popular orchestration tools and local model runners, including ComfyUI, Ollama, and n8n.
- Compromise of web-based interfaces and AI workflow builders such as Open WebUI, Langflow, and Gradio.
- Impact Analysis: Cloud Credential Harvesting
- Systematic exfiltration of high-value AWS Access Keys and Secret Keys.
- Theft of Kubernetes (K8s) service account tokens to enable lateral movement within containerized clusters.
- Reported scale includes the management of 3,811 unique harvested AWS credentials via a dedicated operator dashboard.
- Defensive Recommendations: Hardening AI Infrastructure
- Eliminate public-facing exposure of AI management interfaces, orchestration tools, and local model runners.
- Enforce strict Principle of Least Privilege (PoLP) for all AWS IAM roles and Kubernetes identities.
- Implement robust egress filtering and monitoring for unauthorized API calls and anomalous outbound traffic from AI environments.
Related posts
- gbhackers.com — New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
- serisec.com — New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
- serisec.com — NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure
- cybersecurity.pk — New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
- feeds.feedburner.com — New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
- Cyberpress
- Cypro
- Buttondown
- Thedailytechfeed