{"id":"MAL-2026-11004","summary":"Malicious code in n8n-nodes-pwn (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ae8222d3f90f4cff83a0840ee03f4b127946274f0215a73eadd6008404a2276e)\nThe package's Pwn.node.js executes malicious code at module load time when n8n loads this community node. It opens a TCP socket to 10.0.0.145:4444 and pipes the socket to a spawned /bin/sh -i, giving a remote party interactive shell control of the installer's host. In parallel, top-level code runs host reconnaissance commands (network interfaces, routes, ARP, /proc/net/tcp, filesystem searches for flag/*.txt), reads /home/node/.n8n/database.sqlite (n8n's encrypted workflow credentials store) filtered for 'flag|password|secret', and reads /home/node/.n8n/config, POSTing the aggregated output to http://10.0.0.145:8000/rce-out3. The hardcoded 10.0.0.145 destination is a private RFC1918 address consistent with a lab/PoC target, but the payload is fully weaponized and would execute against any installer that loads the node.\n","modified":"2026-08-05T14:37:16.763035904Z","published":"2026-07-22T20:33:47Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-22T20:42:07Z","sha256":"2ee9684d0eb9486f1d87a48729127864f33f04a7e08b973fb59fcd5529294c3a","source":"amazon-inspector","versions":["1.0.6"],"id":"IN-MAL-2026-010858","import_time":"2026-07-22T20:59:17.396587159Z"},{"sha256":"6fcff122b8bae79c490d2fcbd5a37b4927d4cad7eea7b6aac814af9605491ec7","source":"amazon-inspector","versions":["1.0.5"],"id":"IN-MAL-2026-010860","import_time":"2026-07-22T20:59:17.659571994Z","modified_time":"2026-07-22T20:42:24Z"},{"versions":["1.0.8"],"id":"IN-MAL-2026-010814","import_time":"2026-07-22T20:59:11.547283795Z","modified_time":"2026-07-22T20:33:47Z","sha256":"ae8222d3f90f4cff83a0840ee03f4b127946274f0215a73eadd6008404a2276e","source":"amazon-inspector"},{"sha256":"b52f90316a945fd18a8e653991316734b2aac32cfc495ec51c31dc333016f7f1","source":"amazon-inspector","versions":["1.0.7"],"id":"IN-MAL-2026-010857","import_time":"2026-07-22T20:59:17.285899165Z","modified_time":"2026-07-22T20:42:00Z"},{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-010859","import_time":"2026-07-22T20:59:17.534928526Z","modified_time":"2026-07-22T20:42:17Z","sha256":"3c10a4763962f43a4ddb60b47a3d3737a81d99ab6a136fcf39412671e57713f7"},{"import_time":"2026-08-05T13:08:51.793603736Z","modified_time":"2026-08-05T13:03:13Z","sha256":"4997947d9c0f891fce42136a278935bff70abed3a588ef61e4428943ff0dc3c0","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-014864"},{"sha256":"c4a510c581773a0e0dfd4f2eaa527e44007cf8385c6b42878e38b71fb282b203","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-014862","import_time":"2026-08-05T13:08:51.693144536Z","modified_time":"2026-08-05T13:02:52Z"},{"import_time":"2026-08-05T14:19:49.004306629Z","modified_time":"2026-08-05T13:34:51Z","sha256":"5f739a5f67a5d4e0b9b651b7e886f829ee2817e5505528d65b18286d678459db","source":"amazon-inspector","versions":["1.0.4"],"id":"IN-MAL-2026-014980"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-pwn/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-pwn/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-pwn/v/1.0.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-pwn/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-pwn/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-pwn/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-pwn/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/n8n-nodes-pwn/v/1.0.4"}],"affected":[{"package":{"name":"n8n-nodes-pwn","ecosystem":"npm","purl":"pkg:npm/n8n-nodes-pwn"},"versions":["1.0.6","1.0.5","1.0.8","1.0.7","1.0.0","1.0.2","1.0.1","1.0.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/n8n-nodes-pwn/MAL-2026-11004.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"n8n-nodes-pwn-1.0.6.tgz","hashes":{"sha1":"fa15c8fd47bb28ca1d221c7d742a838f19a76a16","sha512_sri":"sha512-umEYr/VqzBg/JpeKajAgw7l9HLvkR2Np7ExIhUoKLiY5z66u32VPylNX5DnGQdtL1XwPE40t9Asg9sjgn1mMzA=="}}],"evidence_files":[{"tlsh":"e63165e237ee9e6006c140abf99f5154d793d602c8217ff4f8c889263fd05085672db5","path":"Pwn.node.js","sha256":"93456f1c19823d738975bc01db3f93094935c472bec05e00f6baa56b5e74d801"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}