NadMesh is a Go-based botnet discovered in July 2026 that targets exposed AI services to steal cloud credentials and Kubernetes tokens. It uses a Shodan harvester to scan for services like ComfyUI, Ollama, and n8n, and employs multiple persistence mechanisms and obfuscation techniques to evade detection.