The record
Written from the 1 report below. Nothing here is unsourced.
- A new Go botnet called NadMesh is scanning the internet for exposed AI and development services like ComfyUI, Ollama, n8n, Gradio, and Langflow to steal cloud credentials, Kubernetes tokens, and API keys from environment variables and config files.
- QiAnXin's XLab reported it on Friday, noting the operator's dashboard claims 3,811 unique AWS keys, though the panel's own numbers are inconsistent.
- The operator appears focused on cloud access rather than the hosts themselves, with MCP command execution at the top of its exploitation priorities, while Docker APIs and Jenkins consoles absorb most observed exploit traffic.
- The malware persists in three ways at once and uses randomized obfuscation, so single hash-based detection and simple removal will not work.
What to watch next
- Whether XLab or other firms confirm real-world cloud account compromises beyond the operator's self-reported dashboard figures
- Updates on the recently disclosed CVE-2026-39987 (Marimo) and CVE-2026-41176 (rclone) already in NadMesh's exploit list
- Growth of NadMesh scanning activity after it went from near zero to roughly 139 distinct source IPs a day in early July
Coverage1
1 report
English national1
All filed from India
Named United States · China · AWS · ComfyUI · Docker · Gradio · Jenkins · Kubernetes · Langflow · Model Context Protocol · n8n · Ollama · Open WebUI · Redis
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
