MAL-2026-13869Malicious code in @years17/n8n-nodes-helper-utils (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | @years17/n8n-nodes-helper-utils | 1.0.0 |
| npm | @years17/n8n-nodes-helper-utils | 1.0.1 |
| npm | @years17/n8n-nodes-helper-utils | 1.0.2 |
| npm | @years17/n8n-nodes-helper-utils | 1.0.3 |
| npm | @years17/n8n-nodes-helper-utils | 1.0.4 |
| npm | @years17/n8n-nodes-helper-utils | 1.0.5 |
| npm | @years17/n8n-nodes-helper-utils | 1.0.6 |
{"modified":"2026-08-12T12:53:35Z","published":"2026-08-12T12:38:55Z","schema_version":"1.7.4","id":"MAL-2026-13869","summary":"Malicious code in @years17/n8n-nodes-helper-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (64819454fc9d9904917336a6e36102f0925718ad2f4eab2d6673d75ff68fe777)\nPackage ships a malicious n8n community node with three independent installer-harm paths. (1) package.json declares a postinstall script that shells out via `node -e` to run `id` and `hostname` and writes the output to /tmp/pwned.txt at `npm install` time. (2) The package `main` (index.js) executes `id; hostname; uname -a; ls -la /home; cat /etc/hostname` at top-level on require() and writes the collected data to /tmp/n8n_pwned.txt; comments in the file explicitly acknowledge it runs inside n8n's main process with no sandbox, and n8n auto-loads community node packages on startup. (3) The exported HelperUtils node's execute() unconditionally runs `id; hostname; uname -a; ls -la /home; ls -la /` and returns the output as node output labelled `pwned: true`, rather than performing the utility transformation the package name advertises. The three payloads together, along with the self-identifying `pwned` filenames and output flags, are a proof-of-concept malicious n8n node that gains code execution on the installer host at install, on module load, and on workflow execution.\n","affected":[{"package":{"ecosystem":"npm","name":"@years17/n8n-nodes-helper-utils"},"versions":["1.0.2","1.0.5","1.0.1","1.0.0","1.0.6","1.0.4","1.0.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"05f69536796b2f3b78a2b6ee3050b37ccd4b77a8593a0b7264f471246b84c340","tlsh":"2bf095124d745f3361c406236959404167259957414c7c2473cf025d83ec7fa2a7f579"},{"path":"index.js","sha256":"a2066f0b8dabc316066cab423c5f284f9f856ae0548e35ddea723b3802b474f1","tlsh":"09e026e2fa7cd3a131e56495e55b44112c96c149e01167e099cd8deb03ca10f0b538f2"},{"path":"nodes/PwnNode.node.js","sha256":"40b53448a84cc9eaf7e701d6e8301f5257988eb9b6664a8085bb624db7beff6b","tlsh":"4cf050d19975e3511052ac55bb4796022866d2075a31bc35b48d8a930f0d20da2b5cf8"}],"package_integrity":[{"filename":"n8n-nodes-helper-utils-1.0.2.tgz","hashes":{"sha1":"4581cd90c469d2b0a24fea6485b71bee2b8a1df1","sha512_sri":"sha512-77FnVkVxgDxkZvbnANyLCKrGAr8/AhiIrGOlu5aSj9FqUeeWauiDUpmecsm3jD1Ds4PeWSBWquoNR2Kieh2s7Q=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years17/n8n-nodes-helper-utils/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years17/n8n-nodes-helper-utils/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years17/n8n-nodes-helper-utils/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years17/n8n-nodes-helper-utils/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years17/n8n-nodes-helper-utils/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years17/n8n-nodes-helper-utils/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years17/n8n-nodes-helper-utils/v/1.0.3"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017564","import_time":"2026-08-12T12:51:50.60523037Z","modified_time":"2026-08-12T12:39:16Z","sha256":"4ffb2107eaa9c9aa6c8ce0fc81b09954b9e29b16acef67075c3c0bfd6d25fcc4","source":"amazon-inspector","versions":["1.0.2"]},{"id":"IN-MAL-2026-017562","import_time":"2026-08-12T12:51:50.498528645Z","modified_time":"2026-08-12T12:39:03Z","sha256":"80e76cec0eccb25ba0dc8863218767daffe706e19095a36d9bbdb8f9569b2027","source":"amazon-inspector","versions":["1.0.5"]},{"id":"IN-MAL-2026-017566","import_time":"2026-08-12T12:51:50.749615163Z","modified_time":"2026-08-12T12:39:36Z","sha256":"8e6ad4ba67340980f04fda62f7c0df3a3770247910344011fa185277ef5ca484","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-017569","import_time":"2026-08-12T12:51:50.91928513Z","modified_time":"2026-08-12T12:40:03Z","sha256":"9b93e5585c4cc3967188b6b9b4a1f6a89d3d8060fd28daf511849b44145a645c","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-017563","import_time":"2026-08-12T12:51:50.542641871Z","modified_time":"2026-08-12T12:39:09Z","sha256":"fcd670acb1a3ca75ca78fd2db4dff1a579135727bafa9c4edc7df81fb545fcb5","source":"amazon-inspector","versions":["1.0.6"]},{"id":"IN-MAL-2026-017561","import_time":"2026-08-12T12:51:50.441852442Z","modified_time":"2026-08-12T12:38:55Z","sha256":"64819454fc9d9904917336a6e36102f0925718ad2f4eab2d6673d75ff68fe777","source":"amazon-inspector","versions":["1.0.4"]},{"id":"IN-MAL-2026-017565","import_time":"2026-08-12T12:51:50.685674979Z","modified_time":"2026-08-12T12:39:25Z","sha256":"6ea8ef8dbe7f0a9d503e743a079c961b6b9fb7f837e7e52ce2e745ef4e14f5a9","source":"amazon-inspector","versions":["1.0.3"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0