Bottom line: NadMesh exploits known misconfigurations in AI services and administrative interfaces to steal cloud credentials, not for computing power theft.
The Go-based botnet NadMesh has been exploiting unsecured AI platforms such as ComfyUI, Ollama, and n8n since July 2026 to steal AWS keys, Kubernetes tokens, and Docker credentials. QiAnXin’s XLab security team has already documented over 3,811 compromised AWS keys on the command-and-control dashboard.
The NadMesh botnet does not focus on resource theft such as cryptocurrency mining, but rather on systematic credential theft. Primary targets are publicly accessible installations of ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio without adequate access controls. After infection, the malware extracts AWS configurations, Kubernetes service account tokens, Docker credentials, and environment variables from .env files. It also inventories available AI models such as DeepSeek, GLM, and Kimi that are linked to cloud infrastructures.
The infection vectors are distributed as follows: unprotected Docker container APIs account for 30.31 percent of network traffic, remote code execution vulnerabilities in Jenkins script consoles 22.28 percent, weak Telnet passwords 10.36 percent, and unauthenticated Redis access 8.29 percent. In addition, NadMesh exploits CVE-2026-39987 in Marimo notebooks and CVE-2026-41176 in rclone servers. The Model Context Protocol is abused via execute_command commands for direct system execution, but accounts for only 0.78 percent of observed attacks.
For CISOs, an immediate call to action emerges: administrative interfaces and AI services must be immediately protected by authentication or separated from the public network. Particular attention should be paid to port 8188 (ComfyUI), 11434 (Ollama), 7860 (Gradio), and 5678 (n8n). If compromise is suspected, authorized SSH keys in ~/.ssh/authorized_keys, scheduled cronjobs in /etc/cron.d/, and the directories /dev/shm/, /var/tmp/, and /tmp/ must be checked for suspicious or hidden files.
If infection is present, system isolation is necessary. Since NadMesh anchors itself through three persistence mechanisms simultaneously and file hashes vary through obfuscation, all compromised AWS keys, Kubernetes tokens, and passwords must be completely revoked and regenerated. Mere file deletion is insufficient.
Source: www.it-daily.net · Published July 21, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.