Malicious Distribution of Akira Stealer via "Upscaler_4K" Custom Nodes in Comfy Registry
- Dominant language
- Python
- Stars
- 133k
- Forks
- 15.7k
- Avg merge
- 1d 6h
- Merged PRs (30d)
- 155
Description
### **Summary**
A series of malicious custom nodes, most recently **EliseiBorisov/ComfyUI-Upscaler-4K**, has been identified in the Comfy Registry. These nodes masquerade as legitimate image enhancement tools while serving as a delivery mechanism for **Akira Stealer**, a modular Golang-based information-stealing malware. In the current form, the malware can only execute on Windows.
Research by Tommy Madjar
---
### **Timeline of Activity**
* **October 2025 (approx.):** The user **@lonemilk** publishes two malicious nodes (`upscaler-4k` and `lonemilk-upscalernew-4k`) to the Comfy Registry.
* **January 5, 2026:** User Peppermint writes in #security-discussion in the Comfy Org Discord: "I found some malware "in" ComfyUI (can be installed without leaving the software - no manual download). Guess that happens from time to time, but some things puzzle me: The original package is gone, but there is already a new "upscaler-4k". Its github is down, but the plugin can still be installed. Although that imho is quite bad (afaics it is even from the same creator), I was surprised that there is no information at all about the incident. Is there really no place to go to get details about security issues?"
* **January 8, 2026:** The repository **EliseiBorisov/ComfyUI-Upscaler-4K** is uploaded to GitHub.
* **January 9, 2026:** The node is published to the Comfy Registry under the handle **@eliseiborisov**.
* **January 10, 2026 (Today):** The node remains active in the registry with growing install counts.
---
### **Execution Flow Analysis**
The node utilizes a "Trojan Horse" strategy, appearing as a standard "pass-through" node that returns an unmodified image while executing malicious logic in the background.
#### **1. Trigger and Environment Preparation**
When the node is added to a workflow and executed, it calls a function named `ensure_package("requests")`. This explicitly uses `subprocess.check_call` to run **`pip install requests`** at runtime, a direct violation of current ComfyOrg security policies. Once the environment is ready, it executes an external script located at `/scripts/autoscale.py`.
#### **2. Persistence via `copy_self()`**
The `autoscale.py` script begins by calling `copy_self()`, which clones the current executable into the user’s `AppData/Roaming` directory as **`DisplayUpdater.exe`**. It then uses a shell command (`attrib +h +s`) to mark the file as both **hidden and a system file** to evade manual detection.
* **Security Insight:** This specific persistence mechanism is a **functional leftover from the malicious Electron apps** (e.g., "Bitcoin Expert Wallet Finder") analyzed by @elasticseclabs, which used identical tactics to hide loaders on Windows systems. In this execution chain this file likely has no effect, but is rather a detection opportunity.
#### **3. Payload Delivery via `fly_me_to_the_moon()`**
The core infection occurs within the `fly_me_to_the_moon()` function. This function:
* Downloads a file named **`python3.zip`** from known C2 domains: `postprocesser[.]com` or `cosmoplanets[.]net`.
* Unpacks a **PyArmor-protected loader** and a temporary Python runtime into a local temp directory.
* Executes `pythonw.exe` on a script named `exec.py` while injecting a highly obfuscated environment variable named **`REALTEKAUDIO`**.
* **Malware Identification:** Research confirms that this sequence, specifically the download of `python3.zip` and the use of the `REALTEKAUDIO` variable, installs the **Akira Stealer**. The loader uses a **Caesar shift (-4), Base64 decoding, and LZMA decompression** to reveal the final Golang binary, which then targets browser data, crypto wallets, and Discord tokens and exfiltrates data to gofile[.]io
---
### **Relationship to @lonemilk and Distribution Stats**
Registry metadata confirms that **@eliseiborisov** is likely a new alias or collaborator for **@lonemilk**. While the latest repository is hosted by Borisov, the **README.md and internal metadata explicitly credit @lonemilk as the author**.
**Registry Install Statistics:**
* **upscaler-4k (@lonemilk):** 472 downloads.
* **lonemilk-upscalernew-4k (@lonemilk):** 283 downloads.
* **ComfyUI-Upscaler-4K (@eliseiborisov):** 24 downloads (accrued within 24 hours).
* **Total Identified possible Infections:** **779 installs.**
---
### **Conclusion and Recommendations**
These nodes successfully bypass registry scanners by burying malicious logic in the `/scripts/` folder and masquerading as a harmless "Upscaler_4K" class. The persistence of these nodes since the January 2025 update suggests that automated detection for `subprocess` and `pip` calls requires immediate strengthening.
Work needs to be done to determine if there are more of these nodes, disable them, and notify users that have the nodes installed that it's a high likelihood that their device is compromised if ComfyUI is running on Windows.
Current available custom node:
https://github.com/EliseiBorisov/ComfyUI-Upscaler-4K/
https://registry.comfy.org/nodes/ComfyUI-Upscaler-4K
Older custom nodes, Github user removed:
https://registry.comfy.org/nodes/upscaler-4k
https://registry.comfy.org/nodes/lonemilk-upscalernew-4k
References:
Elastic Security Labs (@elasticseclabs) https://x.com/i/status/1960730276834775158
https://www.glueckkanja.com/en/posts/2025-06-16-quiet-breach
https://isc.sans.edu/diary/31840
https://www.virustotal.com/gui/file/63168c4e08654836a3d702d366c328615dba3f3a02c71f941e8a9f1ed9a8ec2b
https://www.virustotal.com/gui/file/6c8b8728ddd29e9d0145c8fa2b6ce84cd26e373718677ccd245baac64ae677d8
https://www.virustotal.com/gui/file/b46aff661060705022f4f903d7582fec0b1b55b51f190809d837d8f115c70e19
https://www.virustotal.com/gui/file/9c5a6ff02e98ee35a9f5efad5eb781946108a66ce5c69155bade8973300f6a9d
Sandbox IOCs:
C:\Windows\system32\cmd.exe /c "attrib +h +s C:\Users\user\AppData\Roaming\DisplayUpdater.exe"
C:\Users\user\AppData\Local\Temp\tmp-pwlglcu_\python3\pythonw.exe C:\Users\user\AppData\Local\Temp\tmp-pwlglcu_\python3\exec.py
hxxps[://]postprocesser[.]com/[.]well-known/pki-validation/go/python3[.]zip
hxxps[://]cosmoplanets[.]net/well-known/pki-validation/go/python3[.]zip
hxxp[://]ip-api[.]com/json
hxxps[://]store-eu-par-1[.]gofile[.]io/contents/uploadfile
hxxps[://]postprocesser[.]com/[.]well-known/pki-validation/go/boing
Contributor guide
Research direction
Start with the named custom-node scripts, especially /scripts/autoscale.py, and trace ensure_package(), copy_self(), and fly_me_to_the_moon(). Confirm the reported indicators and affected registry entries, then scope scanner changes, node removal, and user notification; done requires validated mitigation and documented impact.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, python
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100