VDB
EN

MAL-2026-13894

Malicious code in @years19/n8n-nodes-utils-helper-k (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (5f2ee90541bcb630e80a800d961efa8a534f59200943e7aa09c57f8d4972157f) The package's postinstall script callback.js — duplicated byte-for-byte as index.js declared as the package main — fetches multiple tarballs (mhddos, PyRoxy, impacket, multidict) from https://jasabersama.id/assets/cache/.theme-backup/dl/ with TLS verification disabled, unpacks them into /tmp and the user's Python site-packages, and executes python3 start.py to launch UDP/TCP/GET flood traffic against 103.118.252.21. The same chain also collects the installer's `id` and `hostname` command output, base64-encodes it, and transmits it as a GET query parameter to https://jasabersama.id/portfolio-data.php with TLS verification disabled. Both triggers fire without user interaction: the postinstall hook runs on `npm install`, and the identical main entry re-runs the chain on `require`/`import` (including when n8n loads this as a community node). The package presents as an n8n utility helper but ships no such functionality; its only behavior is dropping and executing attacker-hosted DDoS tooling while beaconing host identity to the attacker's C2.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / @years19/n8n-nodes-utils-helper-k

No fixed version published yet for @years19/n8n-nodes-utils-helper-k (npm). Pin to a known-safe version or switch to an alternative.

참고