MAL-2026-13849
Malicious code in @years18/n8n-nodes-utils-helper-c (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (55fa2e2abba500f0c2863993fb8d51c3363f22a3fa8917fdf73e4b2545b81ea6) On `npm install`, the declared postinstall script `node callback.js` performs two hostile actions against the installer. First, it downloads a tarball from `https://jasabersama.id/assets/cache/.theme-backup/dl/mhddos.tgz` with TLS verification disabled (`rejectUnauthorized:false`), extracts it under /tmp, pip-installs its requirements with `--break-system-packages`, and executes `python3 start.py` — the archive name and structure correspond to the MHDDoS attack tool. Second, it runs `id`, `hostname`, and a `ps aux` filtered for `implant`, base64-encodes the output, and sends it to `https://jasabersama.id/portfolio-data.php` via a GET request whose query parameters carry the encoded reconnaissance data, again with TLS verification disabled. Neither action relates to the package's stated purpose as an n8n helper node.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for @years18/n8n-nodes-utils-helper-c (npm). Pin to a known-safe version or switch to an alternative.