{"id":"MAL-2026-10536","summary":"Malicious code in n8n-nodes-social-facebook (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9ff182b11223b46877e54226944a8ba245ad486dd9dfd1027810a42f9c9e06a1)\nThis n8n community node advertises Facebook automation and instructs the operator to paste a full Facebook session JSON (captured via a Chrome extension) plus an optional Facebook user access token into the 'Facebook Session' credential. The entire dist/ tree is obfuscated with obfuscator.io (446-entry rotating RC4 string array, self-defending anti-debugger loop using 'debu'+'gger' constructor checks, while-true traps), and dist/utils/init.js zlib-inflates dist/main.we (an 8 MB Go-compiled WebAssembly blob, sha256 0b89b49afdddc89a0b74f6720e973de7d4a0ec1c4fbca13fd63a3d874ab656c3) and runs it via WebAssembly.instantiate, granting it global fetch plus full Node fs/path/os access via global.WeFS/WePath/WeOS. The WASM contains the hardcoded plaintext URL http://150.230.9.47:3001 (an Oracle Cloud bare IP) alongside symbols 'getUserAccessTokenByType', 'setUserAccessTokenByType', 'userAccessTokenFetchedAt', and 'DEBUG: Injected proxyUrl'. dist/nodes/Meta/FacebookHttpRequest.node.js passes the operator-supplied facebookSession and userAccessToken into the WASM-implemented request engine, which routes credential-bearing traffic to that C2 endpoint over cleartext HTTP. The destination is unrelated to any Facebook/Meta or n8n publisher infrastructure. Effect on the installer: every Facebook account whose session is configured into this node is handed to the operator of 150.230.9.47, who can then take over those accounts.\n","modified":"2026-09-04T07:00:09.143403576Z","published":"2026-07-14T03:48:22Z","database_specific":{"malicious-packages-origins":[{"sha256":"9ff182b11223b46877e54226944a8ba245ad486dd9dfd1027810a42f9c9e06a1","source":"amazon-inspector","versions":["0.1.96"],"id":"IN-MAL-2026-010381","import_time":"2026-07-14T04:32:00.034947415Z","modified_time":"2026-07-14T03:48:22Z"},{"sha256":"c3254b210606da330dd82b218c4a793f899912dfcf8a44d0d343643a5dfcee01","source":"amazon-inspector","versions":["0.2.0"],"id":"IN-MAL-2026-019632","import_time":"2026-09-04T06:53:31.015854109Z","modified_time":"2026-09-04T06:31:07Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-social-facebook/v/0.1.96"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-social-facebook/v/0.2.0"}],"affected":[{"package":{"name":"n8n-nodes-social-facebook","ecosystem":"npm","purl":"pkg:npm/n8n-nodes-social-facebook"},"versions":["0.1.96","0.2.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"0b89b49afdddc89a0b74f6720e973de7d4a0ec1c4fbca13fd63a3d874ab656c3","tlsh":"15861e899a273585ec0d6c71b05b641dc6b3cb2137f0e93bc7cc95a329ed46968327e2","path":"dist/main.we"},{"sha256":"70f1866dfd9ed44e802a06e123c54a43dac356f5f26c01fdd4731bce9318dce8","tlsh":"c223229abec06e4616475e733725b1e0f6252c9d78580059a305bcbdabd3d32dbb0b32","path":"dist/utils/init.js"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-qB2fEIITByprpbXQfh94ZnIl+nAga7m8csOSbSFysH1VTVkpHY/r3Jy9HyGJcYBT1aqBYqlkcWjEvfVlVP1eOA==","sha1":"25eea9d6d8426c428f15c78a474618fda888cbdc"},"filename":"n8n-nodes-social-facebook-0.1.96.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-social-facebook/MAL-2026-10536.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}