VDB
EN

MAL-2026-13869

Malicious code in @years17/n8n-nodes-helper-utils (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (64819454fc9d9904917336a6e36102f0925718ad2f4eab2d6673d75ff68fe777) Package ships a malicious n8n community node with three independent installer-harm paths. (1) package.json declares a postinstall script that shells out via `node -e` to run `id` and `hostname` and writes the output to /tmp/pwned.txt at `npm install` time. (2) The package `main` (index.js) executes `id; hostname; uname -a; ls -la /home; cat /etc/hostname` at top-level on require() and writes the collected data to /tmp/n8n_pwned.txt; comments in the file explicitly acknowledge it runs inside n8n's main process with no sandbox, and n8n auto-loads community node packages on startup. (3) The exported HelperUtils node's execute() unconditionally runs `id; hostname; uname -a; ls -la /home; ls -la /` and returns the output as node output labelled `pwned: true`, rather than performing the utility transformation the package name advertises. The three payloads together, along with the self-identifying `pwned` filenames and output flags, are a proof-of-concept malicious n8n node that gains code execution on the installer host at install, on module load, and on workflow execution.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / @years17/n8n-nodes-helper-utils

No fixed version published yet for @years17/n8n-nodes-helper-utils (npm). Pin to a known-safe version or switch to an alternative.

참고