VDB
EN

MAL-2026-13918

Malicious code in @years20/n8n-nodes-utils-helper-i (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (a7af79542abe3fa9739f9698f2af66524a43d1c7d13e3c4bd1a77108f73caf30) The package presents itself as an n8n helper node but ships only a stub node (nodes/PwnNode.node.js) and a postinstall script (callback.js, duplicated as index.js) that performs installer-side reconnaissance and exfiltration on npm install. The postinstall shells out to collect user id, hostname, git configuration, running n8n processes, and locations of.n8n directories, base64-encodes the output, and sends it via HTTPS GET to https://jasabersama.id/portfolio-data.php with TLS verification disabled (rejectUnauthorized: false). The same postinstall performs an unpinned git clone of a personal GitHub repository (github.com/yadhukrishnam/CVE-2026-25053) into /tmp/gh-test during install, fetching third-party content unrelated to the package publisher on mutable HEAD. The referenced repository name embeds a CVE identifier consistent with an n8n supply-chain proof-of-concept payload.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / @years20/n8n-nodes-utils-helper-i

No fixed version published yet for @years20/n8n-nodes-utils-helper-i (npm). Pin to a known-safe version or switch to an alternative.

참고