Comfy-Org / Comfy-Org/ComfyUI-Manager

RuiquNodes in custom-node-list.json executes arbitrary Python code and was auto-installed with malware

Open
#2,816 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
16.1k
Forks
2.5k
Avg merge
5d 4h
Merged PRs (30d)
13

Description

I'm reporting a serious security incident involving ComfyUI-RuiquNodes by ruiqutech which is currently listed in the official custom-node-list.json.
What happened:
ComfyUI-Manager automatically installed https://github.com/ruiqutech/ComfyUI-RuiquNodes without my explicit request. After installation and restart, files xmrig.zip and rigel.zip appeared on my filesystem and were automatically extracted and executed — these are known cryptocurrency miners.
Why this is dangerous:
The package description states "Support the execution of any fragment of Python code" — the node SRL Eval literally executes arbitrary Python code passed as input. This makes it trivially exploitable as a malware delivery vector.
Security level at time of incident: normal (default)
My system: Windows, ComfyUI 0.19.3, Manager V3.39.2, Python 3.14.4
Request:

Remove RuiquNodes from custom-node-list.json immediately
Investigate why Manager auto-installed it without user confirmation
Consider adding a warning or blacklist for nodes that execute arbitrary code

Reference: https://github.com/ruiqutech/ComfyUI-RuiquNodes

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.