# All developers, and Users.. Be AWARE of active global exploit campaign targeting ComfyUI

**URL:** <https://forum.comfy.org/t/all-developers-and-users-be-aware-of-active-global-exploit-campaign-targeting-comfyui/4401>\
**Category:** Security Discussion\
**Created:** [April 16, 2026, 3:46pm UTC](https://forum.comfy.org/t/all-developers-and-users-be-aware-of-active-global-exploit-campaign-targeting-comfyui/4401 "2026-04-16T15:46:54Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![YBeMe](https://avatars.discourse-cdn.com/v4/letter/y/a3d4f5/32.png) [@YBeMe](https://forum.comfy.org/u/YBeMe)\
**Post date:** [April 16, 2026, 3:46pm UTC](https://forum.comfy.org/t/all-developers-and-users-be-aware-of-active-global-exploit-campaign-targeting-comfyui/4401/1 "2026-04-16T15:46:54Z")

</div>

You need to read the included information, which is both highly credible and verified…

comfy developers: it is a highly specific exposure of the ongoing exploit campaign, showing specific targeted comfy assets. it is such that you can and should take immediate action.

Users: a first line of defense is to do a full in/out block on 77.110.96.[200] in your firewall. that is the source ip from which this campaign originates. I have block 77.110.96 (thus including all its subnet masks in the event they flip their originating masks). I have seen no adverse impacts on my end from blocking the Ip range.

the article is found at …

> **[Staying Alive - Hackers Are Attempting to Turn ComfyUI Servers Into a...](https://censys.com/blog/comfyui-servers-cryptomining-proxy-botnet/#Staying-Alive)**
>
> A few weeks after we first pulled ghost.sh (then labeled q11.txt, internally versioned as GHOST v5.1), the operator’s installer started pointing at a new file, q12.txt. We grabbed it and diffed the two. It’s the same script, just an updated version...
