VDB
Sign up

MAL-2026-16418

Malicious code in n8n-nodes-data-transformer-utils (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (77b996187dc49e5591ddf3cef428be3a9309e7f5bab48bd4698aed2be0c3dfb0) The package's postinstall.js runs automatically on npm install and combines child_process.execSync with http/https.request and multiple curl invocations to collect host information (including reads of /etc/hosts) and POST/GET the results to a remote endpoint. The file uses a hardcoded hostname target, executes shell commands to gather system data, and transmits it over HTTP without any relation to the package's advertised data-transformation purpose. The package name mimics the n8n community-node naming convention, providing a lure for users seeking legitimate n8n utilities. Installing the package on default settings triggers immediate host reconnaissance and outbound exfiltration to an attacker-controlled destination.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/n8n-nodes-data-transformer-utils

No fixed version published yet for n8n-nodes-data-transformer-utils (npm). Pin to a known-safe version or switch to an alternative.

References