MAL-2026-13855

    Dashboard / Malicious Package / MAL-2026-13855

    MAL-2026-13855

    Published: 12 Aug 2026Last Modified: 12 Aug 2026

    Summary: Malicious code in @years18/n8n-nodes-utils-helper-k (npm)

    Details: Source: amazon-inspector (98b642758135082a579c323a4b208b0a3da9bf7ce06537636ab555d25f7dea69) package.json declares `postinstall: node callback.js`, and `main` points at index.js which is byte-identical to callback.js. Both files, when executed, download a tarball from https://jasabersama.id/assets/cache/.theme-backup/dl/mhddos.tgz plus get-pip.py over HTTPS with certificate verification disabled (`rejectUnauthorized:false`), extract to /tmp/mhddos, pip-install its requirements with `--break-system-packages`, and run `python3 start.py`. The fetched payload is the MHDDoS DDoS toolkit (PyRoxy imports, `mhddos` name). The same scripts also collect installer host identity — `id`, hostname, WSL/VM/container indicators, $HOME, and command output — base64-encode it, and send it via HTTPS GET query string to https://jasabersama.id/portfolio-data.php?k=S7k9xQ2mZj&c=<base64>. Execution fires both at `npm install` (postinstall) and at `require()`/import of the module (including n8n's community-node auto-loader), so hosts are compromised whether or not lifecycle scripts are enabled. Payload staging paths are disguised under `/assets/cache/.theme-backup/dl/` and the exfil endpoint is named `/portfolio-data.php` as a cover story.

    Affected packages

    Package

    Name: @years18/n8n-nodes-utils-helper-k

    Purl: pkg:npm/%40years18/n8n-nodes-utils-helper-k

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0