News
The Malware Is Inside the Workflow: ComfyUI's Custom-Node Supply-Chain Problem
ยท RenderBob team
ComfyUI's custom-node ecosystem is huge, open, and anyone can publish. In 2026 that same openness became a production security problem.

ComfyUI's custom-node ecosystem is huge, open, and anyone can publish. In 2026 that same openness became a production security problem.
Malicious nodes masquerading as image upscalers were caught delivering Akira Stealer, a modular infostealer, using a Trojan horse design: the node passes your image through unchanged while running malicious code in the background, so nothing looks wrong. Even after takedowns, near-identical nodes reappeared in the registry under new handles with growing install counts. Separately, a cryptomining botnet campaign compromised over a thousand publicly accessible ComfyUI instances by exploiting a ComfyUI-Manager vulnerability (CVE-2025-67303, patched in Manager v3.38) that allowed remote code execution on unauthenticated deployments with no user interaction required.
The attack surface is wider than shady nodes. Workflow JSON files, the ones artists freely download and share, can be crafted to exploit vulnerable nodes on whatever server imports them. Most people never security-review a workflow before loading it. With well over a thousand custom-node extensions in circulation and a fast-moving, largely unverified ecosystem, a studio will eventually import something it shouldn't.
For a hobbyist, that is a reinstall-and-change-your-passwords afternoon. For a studio handling client IP under NDA, a credential stealer on a workstation that touches unreleased client material is a breach that can end a client relationship and trigger contractual liability.
The ecosystem is responding. Registry standards now prohibit code obfuscation and runtime subprocess installs, and third-party scanners have appeared to vet nodes before installation. Ad-hoc vetting on each artist's machine does not scale, and it is the wrong place to put a security boundary.
A pipeline where the node registry is curated and vetted centrally, production instances are never exposed to the open internet, the network is segmented, and sensitive work runs offline on owned hardware, turns the custom-node problem from an open door into a controlled one. Put the security boundary in a governed registry.
More from the blog
- Visual Dubbing Goes Mainstream: Prime Video Changes the Mouth, Not the Voice
On 9 September 2026, Prime Video launched AI lip-sync for the English dub of Maxton Hall. Human actors record the dialogue. The actors' mouths are regenerated to match.
- Suggestive Editing Arrives: Story-Aware Rough Cuts Move Into the Mainstream
From Eddie AI's story-structured assemblies at NAB 2026 to Premiere's AI Assistant and Resolve 21 search, editing tools are proposing the cut, not only cleaning the footage.