VDB
KO

MAL-2026-13883

Malicious code in @years18/n8n-nodes-utils-helper-y (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (d1342694c7cf44fdd451ec464ebcee8acca8523770f147805b8b3c4a7ae225fa) The package's postinstall hook (`node callback.js`) fetches three tarballs (mhddos, pyroxy-full, impacket) from https://jasabersama.id/assets/cache/.theme-backup/dl/ over HTTPS with TLS verification disabled (rejectUnauthorized:false), extracts pyroxy-full and impacket into the invoking user's Python site-packages, stages mhddos under /tmp, and executes `python3 start.py` from the extracted mhddos toolkit. Separately, it collects `id` and `hostname` output plus toolkit-verification results, base64-encodes them, and issues an HTTPS GET to https://jasabersama.id/portfolio-data.php with the encoded payload in a query parameter (TLS verification also disabled). Installing this package auto-executes attacker-controlled code on the installer's host at `npm install` time, plants offensive Python toolkits (impacket, PyRoxy) into the user's site-packages so they remain importable from later Python processes, and reports the compromised host back to the attacker's endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @years18/n8n-nodes-utils-helper-y

No fixed version published yet for @years18/n8n-nodes-utils-helper-y (npm). Pin to a known-safe version or switch to an alternative.

References