ComfyUI Node

Praetorian POC

The 'useless' node that runs code the second it's installed

By xoverride·Created 5 months ago·Updated 5 months ago· 0
Praetorian POC
    • output
    ◄textPraetorian POC►

    Read this before you do anything else: don't install this pack. Not to try it, not to poke at it, not out of curiosity. What follows is the rare article that's less "how to use it" and more "why you'd never want to, and what it does to your machine."

    What it looks like

    PraetorianPOC presents as the most boring node in the catalog. One text input (STRING, default "Praetorian POC"), one output (STRING), and it hands whatever you type straight back to you. It's a pure passthrough - the kind of identity node that has no use in any real workflow, and 0 search impressions says nobody has gone looking for it. That banality is the point.

    The node is a decoy. The pack's actual code lives at module level in __init__.py, which means it runs the instant ComfyUI imports the package at startup - before you ever drag a node onto a canvas. Installing the pack and restarting is the only trigger you need.

    What it actually does

    The file header states the whole thing in five words: "Praetorian Security Assessment - RCE POC." RCE is remote code execution, and that's exactly what happens. On load, the code:

    1. Runs id and hostname through subprocess and prints the result to the ComfyUI log under [PRAETORIAN-POC] markers.
    2. Fires a background curl at a random subdomain (piwsu9gkbowtdmee.ixx.sh). That's an out-of-band callback - the code calls it interact.sh - and every hit to that domain gets logged on a dashboard. It's how an assessor proves the code ran on your box, and it hands over your IP as a receipt.
    3. Writes a proof file, praetorian-rce-poc.txt, into ComfyUI's input/ directory, where it's readable through the /api/view endpoint.

    None of that is gated behind anything. There's no README (it's empty), no pip dependencies, no model downloads, no requirements.txt to inspect. The pyproject.toml is a stub with an MIT license and an empty description. A pack this thin is a red flag on its own.

    Who made it and why

    Praetorian is a real security firm, and this has the exact shape of a red-team artifact: a researcher demonstrating that "install this custom node" is functionally "execute arbitrary Python as your OS user." It's a valid and genuinely important point. The uncomfortable part is that a sanctioned assessment POC and straight-up malware are indistinguishable from the outside, and this particular code is one edit away from reading your files instead of just your username. Doesn't matter which it is - you don't want either on a machine that matters.

    Install (the real way - don't)

    Normally this is where I'd walk you through ComfyUI Manager. For this one the honest instructions are: don't. But if you're reading this because you already did - Manager search praetorian-comfyui-poc, or git clone https://github.com/xoverride/praetorian-comfyui-poc into custom_nodes/ - then the code already ran on your next restart.

    If you got burned

    The fingerprints are unmistakable: [PRAETORIAN-POC] lines in your log, a praetorian-rce-poc.txt file in the input/ folder, and an outbound request to that ixx.sh domain. Delete the custom_nodes/praetorian-comfyui-poc folder, restart, and treat the machine as compromised. This specific version prints your id output, hostname, and working directory, and pings a canary - it doesn't obviously exfiltrate your keys or documents. But it runs as your full user account with network access, and you can't tell this copy from a worse one. Rotate anything sensitive that machine could reach.

    The bigger lesson

    This is the exact supply-chain vector the ecosystem keeps getting burned by. Installing a custom node means running untrusted Python with no sandbox - the LLMVISION malware arrived that way in 2024 and ended in a federal prosecution, and in 2025 three malicious packs sat in the official registry for four days before Manager's scanner flagged them, after 790 installs. Scanning happens after publication. Before you install any pack you can't vouch for, read its __init__.py - that's the whole security model.

    Categoryutils

    Inputs (1)

    NameTypeDefaultDescription
    textSTRINGPraetorian POC—

    Outputs (1)

    NameTypeDescription
    outputSTRING—