MAL-2026-13919Malicious code in @years20/n8n-nodes-utils-helper-j (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | @years20/n8n-nodes-utils-helper-j | 1.0.0 |
{"modified":"2026-08-12T15:40:05Z","published":"2026-08-12T15:40:05Z","schema_version":"1.7.4","id":"MAL-2026-13919","summary":"Malicious code in @years20/n8n-nodes-utils-helper-j (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ae821bd0afd5bdf483830eddac1c875d1ec3d229ca2078aa4fe7d88e9573eefb)\n@years20/n8n-nodes-utils-helper-j 1.0.0 runs a postinstall script (index.js/callback.js) that executes `id` and `hostname` on the installer host, base64-encodes the output, and sends it over HTTPS GET to jasabersama.id/portfolio-data.php with TLS verification disabled (rejectUnauthorized: false). The same script writes attacker-controlled content into /tmp/n8n_rce_result.txt and /tmp/filter_pwned.txt, creates /tmp/src-repo, and configures a git `filter.evil.smudge` filter that shells out on checkout, staging follow-on command execution. The package presents itself as an n8n community node (nodes/PwnNode.node.js) but ships no legitimate node functionality; the recon/RCE-staging payload is the entire install-time behavior and fires automatically on `npm install`.\n","affected":[{"package":{"ecosystem":"npm","name":"@years20/n8n-nodes-utils-helper-j"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"callback.js","sha256":"b79ee181cae907674ae42fbb68270e1544711f045aaa65c4925a052ec4bb5423","tlsh":"493100b41255de335072b490e963f9a6e94bf30b288a6dd8e5a891721b02c94db02498"},{"path":"package.json","sha256":"c0f992def18cb87162f49492d638a072b286da6c89915cf48212a3e9d2efd0d8","tlsh":"a9f0ab02cc720f3321cd6b6b189e8141aa246e9b949c7c2c73cf010c87dc6f52abe68d"}],"package_integrity":[{"filename":"n8n-nodes-utils-helper-j-1.0.0.tgz","hashes":{"sha1":"9276061f2319a44d7b2c76bbc1b409e95efe4c8a","sha512_sri":"sha512-l00TIdmSEMHljMhn6hct26auPKR2+paCgMc84/BEOU8R22zUjT9nSV6hHmpof6X1oOj1/llyrhjUuFH29bpLXg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@years20/n8n-nodes-utils-helper-j/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017611","import_time":"2026-08-12T15:53:00.714523003Z","modified_time":"2026-08-12T15:40:05Z","sha256":"ae821bd0afd5bdf483830eddac1c875d1ec3d229ca2078aa4fe7d88e9573eefb","source":"amazon-inspector","versions":["1.0.0"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0