ComfyUI exposure abuse for mining and proxying
Case score 57
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 57
- Main story score
- 57
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
- Campaign The campaign itself is the full case anchor and accounts for the entire compound score. main
Overview
ComfyUI deployments targeted for botnet enrollment
An active campaign targets internet-exposed ComfyUI deployments with a purpose-built Python scanner that sweeps cloud IP ranges, checks for ComfyUI-Manager, installs a vulnerable node package when needed, and weaponizes custom nodes for unauthenticated remote code execution. Compromised hosts are added to a cryptomining stack using XMRig and lolMiner, enrolled in a Hysteria V2 botnet, and subjected to persistence and cleanup steps including repeated shell-script downloads, prompt-history wiping, LD_PRELOAD hiding, and chattr +i locking; more than 1,000 publicly-accessible ComfyUI instances are in scope.