NadMesh Botnet Harvests 3,800+ Cloud Credentials by Targeting Exposed AI Services
A Go-based botnet called NadMesh, discovered in early July 2026, is systematically scanning for and exploiting exposed AI services including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio to steal cloud credentials. The operator's dashboard claims to have collected 3,811 unique AWS keys along with Kubernetes tokens.