News

The Malware Is Inside the Workflow: ComfyUI's Custom-Node Supply-Chain Problem

ยท RenderBob team

ComfyUI's custom-node ecosystem is huge, open, and anyone can publish. In 2026 that same openness became a production security problem.

A concealed malicious core inside an ordinary custom node reaches toward models, credentials, and client media until an inspection beam isolates it.

ComfyUI's custom-node ecosystem is huge, open, and anyone can publish. In 2026 that same openness became a production security problem.

Malicious nodes masquerading as image upscalers were caught delivering Akira Stealer, a modular infostealer, using a Trojan horse design: the node passes your image through unchanged while running malicious code in the background, so nothing looks wrong. Even after takedowns, near-identical nodes reappeared in the registry under new handles with growing install counts. Separately, a cryptomining botnet campaign compromised over a thousand publicly accessible ComfyUI instances by exploiting a ComfyUI-Manager vulnerability (CVE-2025-67303, patched in Manager v3.38) that allowed remote code execution on unauthenticated deployments with no user interaction required.

The attack surface is wider than shady nodes. Workflow JSON files, the ones artists freely download and share, can be crafted to exploit vulnerable nodes on whatever server imports them. Most people never security-review a workflow before loading it. With well over a thousand custom-node extensions in circulation and a fast-moving, largely unverified ecosystem, a studio will eventually import something it shouldn't.

For a hobbyist, that is a reinstall-and-change-your-passwords afternoon. For a studio handling client IP under NDA, a credential stealer on a workstation that touches unreleased client material is a breach that can end a client relationship and trigger contractual liability.

The ecosystem is responding. Registry standards now prohibit code obfuscation and runtime subprocess installs, and third-party scanners have appeared to vet nodes before installation. Ad-hoc vetting on each artist's machine does not scale, and it is the wrong place to put a security boundary.

A pipeline where the node registry is curated and vetted centrally, production instances are never exposed to the open internet, the network is segmented, and sensitive work runs offline on owned hardware, turns the custom-node problem from an open door into a controlled one. Put the security boundary in a governed registry.

More from the blog

All posts