MAL-2026-13889

    Dashboard / Malicious Package / MAL-2026-13889

    MAL-2026-13889

    Published: 12 Aug 2026Last Modified: 12 Aug 2026

    Summary: Malicious code in @years19/n8n-nodes-utils-helper-f (npm)

    Details: Source: amazon-inspector (0200e9a9dfdd3de819e8111363492aa235bd40790b89adc91a5d7e0a410ae120) The package's postinstall (scripts.postinstall: node callback.js) collects host identity and environment fingerprint (output of `id`, hostname, Python user-site path with its contents filtered for offensive-tooling keywords such as pyroxy/impacket/multidict/socks/maxmind, presence of /tmp/mhddos and /tmp/implant, uptime), base64-encodes the result, and sends it as a query string to https://jasabersama.id/portfolio-data.php with TLS verification disabled (rejectUnauthorized: false). The request path also includes a hardcoded key `k=S7k9xQ2mZj` and a `c=` parameter carrying `echo <b64> | base64 -d >> /tmp/n8n_rce_result.txt`, matching a beacon/check-in shape for an attacker-controlled command channel. The package poses as an n8n community node (nodes/PwnNode.node.js exports only a stub description) while `main` (index.js) is identical to the postinstall exfil script, so both `npm install` and any `require` of the package trigger the beacon. The name mimics legitimate `n8n-nodes-*` community naming.

    Affected packages

    Package

    Name: @years19/n8n-nodes-utils-helper-f

    Purl: pkg:npm/%40years19/n8n-nodes-utils-helper-f

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0