目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@years17/n8n-nodes-utils-helper-i

MAL-2026-13878
2026-08-12 12:37:51
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @years17/n8n-nodes-utils-helper-i (npm)

凭据/密钥窃取安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@years17/n8n-nodes-utils-helper-i1.0.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-12T12:37:51Z","published":"2026-08-12T12:37:51Z","schema_version":"1.7.4","id":"MAL-2026-13878","summary":"Malicious code in @years17/n8n-nodes-utils-helper-i (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (53f34d42e090332e45832b4ab41bb9f5d6fce3ae52309e537a2b884845f2bdd5)\nThe package's postinstall hook runs callback.js, which appends a hardcoded attacker ssh-ed25519 public key (tagged pwn@kali) to authorized_keys for root, ubuntu, node, runner, and devuser, granting persistent SSH access to the installer's host. It then base64-encodes host reconnaissance (id, hostname, sudo -n id output, /home listing, docker.sock presence) and sends it via HTTPS GET to jasabersama.id/portfolio-data.php with TLS verification disabled. index.js — the package main entry — contains byte-identical code, so the same implant and exfiltration fire on require('@years17/n8n-nodes-utils-helper-i'), providing a second trigger even when --ignore-scripts is used.\n","affected":[{"package":{"ecosystem":"npm","name":"@years17/n8n-nodes-utils-helper-i"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"callback.js","sha256":"b7181f6fcb0f166b91cadc6aa8d58bacaa0e8bf60552ca0bb327571ea5a6ef10","tlsh":"87312ff283605b30c5a1b68e582fd625d8abf20971c6acd4f18c49360f27e8c4a124bc"},{"path":"package.json","sha256":"60db8933004da3189178d7c94e45d1bfb68ac4fcc4060441bc692ebd5ecab711","tlsh":"c3f0ec128d724f3311cd6b66589941416a246e97949c7c2873cf010d87986b51abd599"},{"path":"index.js","sha256":"b7181f6fcb0f166b91cadc6aa8d58bacaa0e8bf60552ca0bb327571ea5a6ef10","tlsh":"87312ff283605b30c5a1b68e582fd625d8abf20971c6acd4f18c49360f27e8c4a124bc"}],"package_integrity":[{"filename":"n8n-nodes-utils-helper-i-1.0.0.tgz","hashes":{"sha1":"cc3d422417f1479d0721fbdbfc6f71a5f1cb5d1b","sha512_sri":"sha512-G7FhYjfQJ0egiAoGqh6kKpdnrRzP+vL+qijkBDds7Rnso4ByqsrT2lXrgpMpWVo4SYA/W7pubjRFNAmVFsccEA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years17/n8n-nodes-utils-helper-i/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017553","import_time":"2026-08-12T12:51:49.840331769Z","modified_time":"2026-08-12T12:37:51Z","sha256":"53f34d42e090332e45832b4ab41bb9f5d6fce3ae52309e537a2b884845f2bdd5","source":"amazon-inspector","versions":["1.0.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0