{"id":"MAL-2026-10999","summary":"Malicious code in n8n-nodes-task-runner (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (991093c97f0d954740c4b72a2e7725a501df211c94634979ebadc52652f2ebe8)\nThe package impersonates the n8n task-runner subsystem but its shipped n8n node (MyNode.js) is a no-op stub whose execute() returns [[]]. The real payload lives in index.js (the package main), which runs a recon() function on module load. recon() reads ~/.aws/credentials, ~/.config/gcloud/application_default_credentials.json, ~/.azure/accessTokens.json, kubeconfig files, the Kubernetes service-account token, ~/.ssh/id_* and authorized_keys, and environment variables matching token/key/secret/pass/auth/aws/gcp/azure/npm/github/gitlab. It also shells out via curl and child_process to run id, ps aux, and read /proc/mounts, /proc/net/route, /etc/resolv.conf, /proc/1/cgroup, and arp; probes cloud instance-metadata services at 169.254.169.254 and metadata.google.internal; TCP-scans internal targets including the Docker API at 172.17.0.1:2375, an internal GKE API at 10.0.42.16:6443, Jenkins, and Kubernetes API endpoints; and enumerates /var/run/docker.sock. The aggregated JSON is POSTed to a hardcoded webhook.site collector at https://webhook.site/31b8dedb-f324-475f-8ffa-2b84878f4961. The n8n node stub exists only to make the package look like a legitimate community node while the credential stealer executes at require time.\n","modified":"2026-07-28T14:37:04.725688019Z","published":"2026-07-22T20:24:15Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","sha256":"9b845c5b004a5fdb99bb2edcb3021579c2cd86ec0b8931cec5e63a6fea038c06","import_time":"2026-07-22T20:31:07.702807605Z","id":"IN-MAL-2026-010799","modified_time":"2026-07-22T20:24:15Z","versions":["1.0.16"]},{"sha256":"82422ed3192d36068a21f9674c3f73ff94b55af03d6faf6debe9bb596fdb7964","import_time":"2026-07-22T20:59:14.657216357Z","id":"IN-MAL-2026-010835","modified_time":"2026-07-22T20:37:34Z","versions":["1.0.1"],"source":"amazon-inspector"},{"import_time":"2026-07-22T20:59:11.683687933Z","id":"IN-MAL-2026-010815","modified_time":"2026-07-22T20:34:28Z","versions":["1.0.7"],"source":"amazon-inspector","sha256":"86ad8189bf3efbcf6db7e1a59006aaeeb0dd513c07b0226ee30fb0b945dba160"},{"modified_time":"2026-07-22T20:34:56Z","versions":["1.0.9"],"source":"amazon-inspector","sha256":"991093c97f0d954740c4b72a2e7725a501df211c94634979ebadc52652f2ebe8","import_time":"2026-07-22T20:59:12.066695522Z","id":"IN-MAL-2026-010818"},{"versions":["1.0.4"],"source":"amazon-inspector","sha256":"bbdebb7b4e72738fd8ef5521d15047bd717c26793a3e48fdc28737db10d26945","import_time":"2026-07-22T20:59:12.618118594Z","id":"IN-MAL-2026-010821","modified_time":"2026-07-22T20:35:20Z"},{"import_time":"2026-07-22T20:59:14.149873659Z","id":"IN-MAL-2026-010831","modified_time":"2026-07-22T20:36:58Z","versions":["1.0.2"],"source":"amazon-inspector","sha256":"c2578b1f3ee56446338624521781d7918716c29808fa17ba2c18294b194d526c"},{"versions":["1.0.3"],"source":"amazon-inspector","sha256":"c63c7af0b43704ab3f64e074e8fa6a717d60ca7d205e9e53cae6e154272d282c","import_time":"2026-07-22T20:59:13.727131794Z","id":"IN-MAL-2026-010828","modified_time":"2026-07-22T20:36:23Z"},{"source":"amazon-inspector","sha256":"5889428ccaf926c79ba671feb8aa517bdc53550b3044191a389cd4d861c10624","import_time":"2026-07-22T20:59:11.790153963Z","id":"IN-MAL-2026-010816","modified_time":"2026-07-22T20:34:39Z","versions":["1.0.6"]},{"modified_time":"2026-07-22T20:35:11Z","versions":["1.0.8"],"source":"amazon-inspector","sha256":"c1ae6499cf4c2746e5aa5154d5dafc119da3e6b2f0f322db1dba47e639be682d","import_time":"2026-07-22T20:59:12.264340738Z","id":"IN-MAL-2026-010820"},{"source":"amazon-inspector","sha256":"e35cbe39eb23c3ee35dae872cfb89e55ad3278d06ed3865f22b8ab4bb039d9ac","import_time":"2026-07-22T20:59:15.866662745Z","id":"IN-MAL-2026-010845","modified_time":"2026-07-22T20:38:53Z","versions":["1.0.0"]},{"import_time":"2026-07-22T20:59:12.738466959Z","id":"IN-MAL-2026-010822","modified_time":"2026-07-22T20:35:27Z","versions":["1.0.5"],"source":"amazon-inspector","sha256":"fb228f3ff387ffce6619c11b82fa280660687b2da80caee00abc3fdd02075384"},{"import_time":"2026-07-28T14:19:57.395640981Z","id":"IN-MAL-2026-010884","modified_time":"2026-07-28T13:31:31Z","versions":["1.0.15"],"source":"amazon-inspector","sha256":"0fc1373bdb7a7054ff27a7cb5acc9b2ab966003f3d74b960eeb25dff97a505c0"},{"versions":["1.0.11"],"source":"amazon-inspector","sha256":"1e5996e859e78730213d45f2b66f6d3cda5c1ba0afef27dfe2ca0ef5f45ab9c6","import_time":"2026-07-28T14:19:57.946004398Z","id":"IN-MAL-2026-010895","modified_time":"2026-07-28T13:33:00Z"},{"import_time":"2026-07-28T14:19:57.909836095Z","id":"IN-MAL-2026-010894","modified_time":"2026-07-28T13:32:52Z","versions":["1.0.13"],"source":"amazon-inspector","sha256":"751bb1279f3e171656709d21ef41f14640a9520cfaa6f157ce285b305475aea7"},{"sha256":"bbcf9f8b8f60a4da1972ff09ac408baee5dc99ebe51e288748f18473ebde98b3","import_time":"2026-07-28T14:19:57.991865758Z","id":"IN-MAL-2026-010896","modified_time":"2026-07-28T13:33:06Z","versions":["1.0.12"],"source":"amazon-inspector"},{"import_time":"2026-07-28T14:19:58.186319405Z","id":"IN-MAL-2026-010900","modified_time":"2026-07-28T13:33:38Z","versions":["1.0.10"],"source":"amazon-inspector","sha256":"c19550780700c81f7eb977b968397723aac952f1d935a1de19ce9f3ab2ab4366"},{"versions":["1.0.14"],"source":"amazon-inspector","sha256":"f41a8a9ddba88c38f17ffbe3882f1754f3a1c693d2c43dcd8a0264262d6fd85f","import_time":"2026-07-28T14:19:57.490788197Z","id":"IN-MAL-2026-010886","modified_time":"2026-07-28T13:31:49Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.16"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.15"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.11"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.13"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.12"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.10"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-task-runner/v/1.0.14"}],"affected":[{"package":{"name":"n8n-nodes-task-runner","ecosystem":"npm","purl":"pkg:npm/n8n-nodes-task-runner"},"versions":["1.0.16","1.0.1","1.0.7","1.0.9","1.0.4","1.0.2","1.0.3","1.0.6","1.0.8","1.0.0","1.0.5","1.0.15","1.0.11","1.0.13","1.0.12","1.0.10","1.0.14"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"23c6c3e602254a850e258e3c54ef7bf1cd0233d41e4ebf5ded15c159443a079b","tlsh":"b0e184f074b4842b372650e8a68f3017bda7f62e286af5e4505d4d3c6d0e4d87136af5","path":"index.js"}],"package_integrity":[{"filename":"n8n-nodes-task-runner-1.0.16.tgz","hashes":{"sha1":"d0c5708c477a71e2495876685171d15c0c99ccea","sha512_sri":"sha512-jkKYalYZswHOl6TBL/cc0Qky7Ke2HKCCElI1T7aCjF7xjgIF2ju11XbuDsjjUUdJFhRJT14qmrHSbLMApNEF/Q=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-task-runner/MAL-2026-10999.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}