VDB
KO

MAL-2026-13869

Malicious code in @years17/n8n-nodes-helper-utils (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (64819454fc9d9904917336a6e36102f0925718ad2f4eab2d6673d75ff68fe777) Package ships a malicious n8n community node with three independent installer-harm paths. (1) package.json declares a postinstall script that shells out via `node -e` to run `id` and `hostname` and writes the output to /tmp/pwned.txt at `npm install` time. (2) The package `main` (index.js) executes `id; hostname; uname -a; ls -la /home; cat /etc/hostname` at top-level on require() and writes the collected data to /tmp/n8n_pwned.txt; comments in the file explicitly acknowledge it runs inside n8n's main process with no sandbox, and n8n auto-loads community node packages on startup. (3) The exported HelperUtils node's execute() unconditionally runs `id; hostname; uname -a; ls -la /home; ls -la /` and returns the output as node output labelled `pwned: true`, rather than performing the utility transformation the package name advertises. The three payloads together, along with the self-identifying `pwned` filenames and output flags, are a proof-of-concept malicious n8n node that gains code execution on the installer host at install, on module load, and on workflow execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @years17/n8n-nodes-helper-utils

No fixed version published yet for @years17/n8n-nodes-helper-utils (npm). Pin to a known-safe version or switch to an alternative.

References