VDB
KO

MAL-2026-13892

Malicious code in @years19/n8n-nodes-utils-helper-i (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (3f484be79b89b443e145029a177ed84e3d55653a6ab1d0f62cec1df2eff70c44) The package's postinstall script executes callback.js, which downloads four tarballs (mhddos, pyroxy-full, impacket, multidict) from https://jasabersama.id/assets/cache/.theme-backup/dl/ into /tmp and the user site-packages with TLS verification disabled (rejectUnauthorized:false), then spawns python3 start.py to launch UDP/TCP/GET flood traffic against the hardcoded target 103.118.252.21. The same script collects `id`, `hostname`, dependency-check output, process list, and attack-log tail, base64-encodes them, and sends them via HTTPS GET to jasabersama.id/portfolio-data.php as a beacon. The package's declared main entry index.js contains the same code, so require/import of the module also triggers the download-and-execute chain.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @years19/n8n-nodes-utils-helper-i

No fixed version published yet for @years19/n8n-nodes-utils-helper-i (npm). Pin to a known-safe version or switch to an alternative.

References