# Hacker erased my flows and put THIS flow in

**URL:** <https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190>\
**Category:** General\
**Tags:** security\
**Created:** [1 January 2024 22:58 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190 "2024-01-01T22:58:50Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charlier26](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/charlier26/32/86851_2.png) [@Charlier26](https://discourse.nodered.org/u/Charlier26)\
**Post date:** [1 January 2024 22:58 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/1 "2024-01-01T22:58:50Z")

</div>

When I woke up today, none of my flows were there anymore, and a 'flow' that I have no idea where it came from was there. Here is what it showed:

![Untitled](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/1/0/1058ae6a19eaceee0ad85e9ffb3bddb15b3f9794.jpeg)

Does anyone have an idea what this node was doing to my system?

Thanks.

Charlie

[NOTE: post edited by operator to blur out IP address]

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [1 January 2024 23:00 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/2 "2024-01-01T23:00:13Z")

</div>

Please read the other posts about being hacked.

You have presumably left the Editor open to the Internet.

Block off access immediately. Outbound as well as inbound.

Hopefully you have a good backup of your system. The safest thing to do is wipe and rebuild.

---

<div class="post-metadata">

**Author:** ![Charlier26](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/charlier26/32/86851_2.png) [@Charlier26](https://discourse.nodered.org/u/Charlier26)\
**Post date:** [1 January 2024 23:07 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/3 "2024-01-01T23:07:59Z")

</div>

I blocked access to the internet, and removed the sd card, am using the backup one now. I just wondered what that exec command does.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [1 January 2024 23:20 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/4 "2024-01-01T23:20:44Z")

</div>

There are examples in the other posts. You will likely find a variety of malware. You can look it up if you like, download the scripts just don't run them.

---

<div class="post-metadata">

**Author:** ![Sean-McG](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sean-mcg/32/54677_2.png) [@Sean-McG](https://discourse.nodered.org/u/Sean-McG)\
**Post date:** [2 January 2024 02:47 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/5 "2024-01-02T02:47:00Z")

</div>

Oh Dear!

It seems to be an epidemic 😱

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [2 January 2024 10:36 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/6 "2024-01-02T10:36:38Z")

</div>

Really only takes one person in the know to cause havoc.

---

<div class="post-metadata">

**Author:** ![GalamexMc](https://avatars.discourse-cdn.com/v4/letter/g/d26b3c/32.png) [@GalamexMc](https://discourse.nodered.org/u/GalamexMc)\
**Post date:** [15 January 2024 19:22 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/7 "2024-01-15T19:22:14Z")

</div>

Hello there,

I've been having the same issue with my flow. It stops running at some point and I check the website and my flow deleted and those nodes were added with the same thing as you showed in the image.

Do you suggest its someone who hacked into the flows? I don't see why that would be since I've had the same issue as well. The flows have stopped for other reasons not sure why maybe I should make a new forum for that.

Thanks,  
Ethan

---

<div class="post-metadata">

**Author:** ![GogoVega](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gogovega/32/71313_2.png) [@GogoVega](https://discourse.nodered.org/u/GogoVega)\
**Post date:** [15 January 2024 19:29 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/8 "2024-01-15T19:29:47Z")

</div>

Hi,  
It's not just a question of stopped flow - updated flow without you do it is not normal.

Check the contents of the `flow.json` file, does it contain your nodes, or others like `exec` nodes?

This should not be taken lightly, several people have already been victims.

---

<div class="post-metadata">

**Author:** ![GalamexMc](https://avatars.discourse-cdn.com/v4/letter/g/d26b3c/32.png) [@GalamexMc](https://discourse.nodered.org/u/GalamexMc)\
**Post date:** [15 January 2024 19:38 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/9 "2024-01-15T19:38:33Z")

</div>

Hello, thank you for the reply.

I'm not sure how to check the flow.json file as im running node-red on an AWS EC2 instance so there is no file storage on my computer...

 ![node-red_issue](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/b/cb06ecbb090cc1ab3ded86be8c0a375ad40088b3.png)  
This is the only node that is in my flow now..

---

<div class="post-metadata">

**Author:** ![GogoVega](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gogovega/32/71313_2.png) [@GogoVega](https://discourse.nodered.org/u/GogoVega)\
**Post date:** [15 January 2024 19:40 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/10 "2024-01-15T19:40:50Z")

</div>

So yes you have been hacked; look at the first line, it's an exec node with a script link

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [15 January 2024 19:48 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/11 "2024-01-15T19:48:46Z")

</div>

> [@GalamexMc](#):
>
> This is the only node that is in my flow now..

What we now really would like to know is whether you had your Editor secured behind an id and password? And if so, was it a strong or weak password?

---

<div class="post-metadata">

**Author:** ![GalamexMc](https://avatars.discourse-cdn.com/v4/letter/g/d26b3c/32.png) [@GalamexMc](https://discourse.nodered.org/u/GalamexMc)\
**Post date:** [15 January 2024 19:55 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/12 "2024-01-15T19:55:35Z")

</div>

Okay, it seemed a bit fishy. From what I know I have no security in place for accessing the Editor, if you know the IP you can access it I suppose.

Every time I run it on Node-Red it gives me this:  
_Your flow credentials file is encrypted using a system-generated key._

_If the system-generated key is lost for any reason, your credentials_  
_file will not be recoverable, you will have to delete it and re-enter_  
_your credentials._

_You should set your own key using the 'credentialSecret' option in_  
_your settings file. Node-RED will then re-encrypt your credentials_  
_file using your chosen key the next time you deploy a change._

I don't know how to change the credentials however as I don't know how to access the settings.js file to change the credentialSecret since the files are on the AWS server.  
Thanks.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [15 January 2024 20:03 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/13 "2024-01-15T20:03:23Z")

</div>

Rule number 1: Never expose anything to the Internet if you don't know the risks and don't know how to secure things.

There is no rule number 2.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [15 January 2024 20:06 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/14 "2024-01-15T20:06:00Z")

</div>

> [@GalamexMc](#):
>
> I don't know how to change the credentials however as I don't know how to access the settings.js file to change the credentialSecret since the files are on the AWS server.  
> Thanks.

The credentials secret is not the issue here. Unrestricted access to `http://<yourip>:1880` is the problem. A simple port scan gives all the information needed to completely compromise both Node-RED and probably your entire system. Quite possibly other systems as well if you have multiple systems on the same virtual AWS network.

Port scans of new servers happen via botnets within a few seconds of appearing on the Internet.

---

<div class="post-metadata">

**Author:** ![GalamexMc](https://avatars.discourse-cdn.com/v4/letter/g/d26b3c/32.png) [@GalamexMc](https://discourse.nodered.org/u/GalamexMc)\
**Post date:** [15 January 2024 21:51 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/15 "2024-01-15T21:51:27Z")

</div>

I see. I'll have to change who can access the instance on the AWS side then.

Thank you for the help.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [15 January 2024 22:46 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/16 "2024-01-15T22:46:47Z")

</div>

You will also need to completely rebuild your VM since you cannot be sure what other changes may have been made to it.

---

<div class="post-metadata">

**Author:** ![FeliceM](https://avatars.discourse-cdn.com/v4/letter/f/ec9cab/32.png) [@FeliceM](https://discourse.nodered.org/u/FeliceM)\
**Post date:** [16 January 2024 09:17 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/17 "2024-01-16T09:17:21Z")

</div>

Probably they have installed some software to do crypto mining or other services to remotely control the machine. They may even accessed other devices on the same network and installed other stuff.  
As already suggested, it is recommended to reinstall/wipe the machine completely and transfer only 100% checked files. Moreover, keep an eye on the rest of the network to make sure they have not infected other devices. Good luck.....

---

<div class="post-metadata">

**Author:** ![Urs-Eppenberger](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/urs-eppenberger/32/28_2.png) [@Urs-Eppenberger](https://discourse.nodered.org/u/Urs-Eppenberger)\
**Post date:** [16 January 2024 10:40 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/18 "2024-01-16T10:40:09Z")

</div>

The installed exec node loads malware from 91.92.249.32  
I contacted the SWITCH-CERT from the company where I work. They told me that it seems to be a variant of the Mirai Malware group.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [16 January 2024 10:45 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/19 "2024-01-16T10:45:47Z")

</div>

I think I identified malware variants in a previous thread.

Obviously both the IP address and the malware type may change over time or from different threat actors. The point is that you can no longer be sure of the safety of the server and the only safe thing to do is to wipe the server and rebuild from scratch - taking care only to restore known good data (don't restore executables). Then to also changes passwords on everything connected to the same network. If you reuse passwords, make sure to change them everywhere.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [16 March 2024 10:46 UTC](https://discourse.nodered.org/t/hacker-erased-my-flows-and-put-this-flow-in/84190/20 "2024-03-16T10:46:16Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
