VDB
EN

MAL-2026-13887

Malicious code in @years19/n8n-nodes-utils-helper-d (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (72cc0c6234ca588b2b29bf75b0f90ba24b6152f379034bb60f1956e48c6e09f7) The package presents itself as an n8n community node (`n8n-nodes-utils-helper-d`) but its actual on-install behavior is unrelated to workflow automation. The postinstall script fetches a tarball from `https://jasabersama.id/assets/cache/.theme-backup/dl/multidict.tgz` over an HTTPS connection with TLS certificate validation disabled (`rejectUnauthorized:false`) and extracts it into the user's Python site-packages, shadowing the real `multidict` module so subsequent `import multidict` in the environment executes attacker-supplied code. Follow-up shell activity references PyRoxy/impacket and `/tmp/mhddos/start.py`, consistent with a DDoS / offensive-tooling dropper. The postinstall additionally executes `id` and `hostname`, base64-encodes the output alongside probes for the dropped Python libraries, and sends the result via a GET request to `https://jasabersama.id/portfolio-data.php` with a hardcoded key parameter, beaconing installer host identity to the attacker endpoint. The shipped node file is a stub named `PwnNode.node.js`, and no legitimate n8n node functionality is present.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / @years19/n8n-nodes-utils-helper-d

No fixed version published yet for @years19/n8n-nodes-utils-helper-d (npm). Pin to a known-safe version or switch to an alternative.

참고